Unauthenticated SQL Injection in WCFM Marketplace Plugin by WordPress
CVE-2026-81286
9.3CRITICAL
What is CVE-2026-81286?
An unauthenticated SQL injection vulnerability exists in versions of the WCFM Marketplace plugin up to 3.8.1. This flaw allows attackers to execute arbitrary SQL commands through specially crafted input, potentially leading to sensitive data exposure or manipulation. Exploiting this vulnerability does not require authentication, making it particularly dangerous for WordPress site owners using this plugin. It's essential to update to a secure version to mitigate these risks.
Affected Version(s)
WCFM Marketplace <= 3.8.1