Unauthenticated SQL Injection in WCFM Marketplace Plugin by WordPress
CVE-2026-81286

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81286?

An unauthenticated SQL injection vulnerability exists in versions of the WCFM Marketplace plugin up to 3.8.1. This flaw allows attackers to execute arbitrary SQL commands through specially crafted input, potentially leading to sensitive data exposure or manipulation. Exploiting this vulnerability does not require authentication, making it particularly dangerous for WordPress site owners using this plugin. It's essential to update to a secure version to mitigate these risks.

Affected Version(s)

WCFM Marketplace <= 3.8.1

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivaylo Atanassov | Patchstack Bug Bounty Program
.