VYPR

Woocommerce Multivendor Marketplace

by WordPress

CVEs (1)

  • CVE-2026-1722MedFeb 10, 2026
    risk 0.34cvss 5.3epss 0.00

    The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.0. This is due to the plugin not implementing authorization checks in the `wcfm-refund-requests-form`…