SQL Injection Vulnerability in WCFM Marketplace Plugin for WordPress
CVE-2026-18442

7.5HIGH

What is CVE-2026-18442?

The WCFM Marketplace plugin for WooCommerce is prone to a SQL Injection vulnerability through the 'wcfmmp_user_location_lng' parameter. This flaw arises from inadequate escaping of user-supplied input and insufficient preparation of SQL queries. As a result, unauthenticated attackers can craft malicious inputs to append their own SQL queries, potentially allowing unauthorized access to sensitive database information. Users are strongly urged to update the plugin to the latest version to mitigate this security risk.

Affected Version(s)

WCFM Marketplace – Multivendor Marketplace for WooCommerce 0 <= 3.8.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonah Burgess (CryptoCat)
.