← Zurück zur CVE-Suche

CVE-2026-2554

WCFM

Beschreibung

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via the -wcfm_delete_wcfm_customer- due to missing validation on the -customerid- user controlled key. This makes it possible for authenticated attackers, with Vendor-level access and above, to delete arbitrary users, including Administrators.

CVSS 8.1EPSS 0.328%Risiko 0.83
Quelle öffnen
Veröffentlicht
2026-05-02 14:16:17
Betroffene Versionen
<=6.7.25
Typ
Installed app
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H