Insecure Direct Object Reference in WCFM Frontend Manager for WooCommerce
CVE-2026-4896

8.1HIGH

What is CVE-2026-4896?

The WCFM – Frontend Manager for WooCommerce and the Bookings Subscription Listings Compatible plugin for WordPress are susceptible to Insecure Direct Object Reference vulnerabilities. All versions up to 6.7.25 may be exploited through multiple AJAX actions such as wcfm_modify_order_status, delete_wcfm_article, and delete_wcfm_product. This security lapse stems from inadequate validation of user-supplied object IDs, enabling authenticated attackers with Vendor-level access or higher to alter the status of orders and manipulate or remove any posts, products, or pages irrespective of ownership.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WCFM – Frontend Manager for WooCommerce 0 <= 6.7.25

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osvaldo Noe Gonzalez Del Rio
.