SQL Injection Vulnerability in WCFM Marketplace Plugin for WordPress
CVE-2026-18442
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-18442?
The WCFM Marketplace plugin for WooCommerce is prone to a SQL Injection vulnerability through the 'wcfmmp_user_location_lng' parameter. This flaw arises from inadequate escaping of user-supplied input and insufficient preparation of SQL queries. As a result, unauthenticated attackers can craft malicious inputs to append their own SQL queries, potentially allowing unauthorized access to sensitive database information. Users are strongly urged to update the plugin to the latest version to mitigate this security risk.
Affected Version(s)
WCFM Marketplace β Multivendor Marketplace for WooCommerce 0 <= 3.8.2