Insecure Direct Object Reference in WCFM Marketplace Plugin for WordPress
CVE-2026-1722

5.3MEDIUM

What is CVE-2026-1722?

The WCFM Marketplace plugin for WordPress is susceptible to an Insecure Direct Object Reference, allowing unauthenticated users to exploit the wcfm-refund-requests-form AJAX controller. This vulnerability enables attackers to submit refund requests for any order ID and item ID without proper authorization. If the plugin settings allow for automatic approval of refunds, this could result in significant financial repercussions for site operators. Users of versions up to and including 3.7.0 should take immediate action to mitigate this risk.

Affected Version(s)

WCFM Marketplace – Multivendor Marketplace for WooCommerce 0 <= 3.7.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gibran Abdillah
.