Insecure Direct Object Reference in WCFM Membership Plugin for WooCommerce by WordPress
CVE-2025-15147
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 February 2026
What is CVE-2025-15147?
The WCFM Membership β WooCommerce Memberships for Multivendor Marketplace plugin for WordPress has a critical issue due to Insecure Direct Object Reference (IDOR). This vulnerability arises from insufficient validation on user-controlled keys within the 'WCFMvm_Memberships_Payment_Controller::processing' method, enabling authenticated attackers with Subscriber-level access or higher to alter other users' membership payment details. This compromise can lead to unauthorized changes in user payments, making it essential for site administrators to address this security flaw by updating to the latest patched version.
Affected Version(s)
WCFM Membership β WooCommerce Memberships for Multivendor Marketplace 0 <= 2.11.8