Insecure Direct Object Reference in WCFM Membership Plugin for WooCommerce by WordPress
CVE-2025-15147
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 February 2026
What is CVE-2025-15147?
The WCFM Membership β WooCommerce Memberships for Multivendor Marketplace plugin for WordPress has a critical issue due to Insecure Direct Object Reference (IDOR). This vulnerability arises from insufficient validation on user-controlled keys within the 'WCFMvm_Memberships_Payment_Controller::processing' method, enabling authenticated attackers with Subscriber-level access or higher to alter other users' membership payment details. This compromise can lead to unauthorized changes in user payments, making it essential for site administrators to address this security flaw by updating to the latest patched version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WCFM Membership β WooCommerce Memberships for Multivendor Marketplace * <= 2.11.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved