PT-2026-30313 · WordPress · Wcfm – Frontend Manager For Woocommerce+1

Published

2026-04-04

·

Updated

2026-04-05

·

CVE-2026-4896

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress versions up to and including 6.7.25
Description The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is susceptible to Insecure Direct Object Reference in multiple AJAX actions, including wcfm modify order status, delete wcfm article, and delete wcfm product, as well as the article management controller. This is due to a lack of validation on user-supplied object IDs. Authenticated attackers with Vendor-level access or higher can modify the status of any order and delete or modify any post, product, or page, regardless of ownership.
Recommendations Update WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress to a version later than 6.7.25.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4896

Affected Products

Bookings Subscription Listings Compatible
Wcfm – Frontend Manager For Woocommerce