Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-4896

Опубликовано: 04 апр. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including wcfm_modify_order_status, delete_wcfm_article, delete_wcfm_product, and the article management controller due to missing validation on user-supplied object IDs. This makes it possible for authenticated attackers, with Vendor-level access and above, to modify the status of any order, delete or modify any post/product/page, regardless of ownership.

EPSS

Процентиль: 1%
0.00012
Низкий

8.1 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.1
github
4 дня назад

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`, `delete_wcfm_product`, and the article management controller due to missing validation on user-supplied object IDs. This makes it possible for authenticated attackers, with Vendor-level access and above, to modify the status of any order, delete or modify any post/product/page, regardless of ownership.

EPSS

Процентиль: 1%
0.00012
Низкий

8.1 High

CVSS3

Дефекты

CWE-639