Insecure Direct Object Reference in WCFM Marketplace Plugin for WordPress
CVE-2026-1722
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2026-1722?
The WCFM Marketplace plugin for WordPress is susceptible to an Insecure Direct Object Reference, allowing unauthenticated users to exploit the wcfm-refund-requests-form AJAX controller. This vulnerability enables attackers to submit refund requests for any order ID and item ID without proper authorization. If the plugin settings allow for automatic approval of refunds, this could result in significant financial repercussions for site operators. Users of versions up to and including 3.7.0 should take immediate action to mitigate this risk.
Affected Version(s)
WCFM Marketplace β Multivendor Marketplace for WooCommerce 0 <= 3.7.0