PT-2026-30313 · Wc Lovers · Wcfm – Frontend Manager For Woocommerce

Published

2026-04-04

·

Updated

2026-04-04

·

CVE-2026-4896

CVSS v3.1

8.1

High

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including wcfm modify order status, delete wcfm article, delete wcfm product, and the article management controller due to missing validation on user-supplied object IDs. This makes it possible for authenticated attackers, with Vendor-level access and above, to modify the status of any order, delete or modify any post/product/page, regardless of ownership.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-4896

Affected Products

Wcfm – Frontend Manager For Woocommerce