CVE-2026-77701 PUBLISHED

WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders

Assigner: WPScan
Reserved: 21.08.2026 Published: 28.08.2026 Updated: 28.08.2026

The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.

Product Status

Vendor Unknown
Product WCFM Marketplace
Versions Default: unaffected
  • affected from 3.7.1 to 3.8.2 (excl.)

Credits

  • Shikhali Jamalzade finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE