CVE-2026-4896 PUBLISHED

WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation

Assigner: Wordfence
Reserved: 26.03.2026 Published: 04.04.2026 Updated: 04.04.2026

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including wcfm_modify_order_status, delete_wcfm_article, delete_wcfm_product, and the article management controller due to missing validation on user-supplied object IDs. This makes it possible for authenticated attackers, with Vendor-level access and above, to modify the status of any order, delete or modify any post/product/page, regardless of ownership.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor wclovers
Product WCFM – Frontend Manager for WooCommerce
Versions Default: unaffected
  • affected from 0 to 6.7.25 (incl.)

Credits

  • Osvaldo Noe Gonzalez Del Rio finder

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE