Insecure Direct Object Reference in WCFM Membership Plugin for WooCommerce by WordPress
CVE-2025-15147

4.3MEDIUM

What is CVE-2025-15147?

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress has a critical issue due to Insecure Direct Object Reference (IDOR). This vulnerability arises from insufficient validation on user-controlled keys within the 'WCFMvm_Memberships_Payment_Controller::processing' method, enabling authenticated attackers with Subscriber-level access or higher to alter other users' membership payment details. This compromise can lead to unauthorized changes in user payments, making it essential for site administrators to address this security flaw by updating to the latest patched version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace * <= 2.11.8

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jing Xuan Sun
.