Descrição
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via the -wcfm_delete_wcfm_customer- due to missing validation on the -customerid- user controlled key. This makes it possible for authenticated attackers, with Vendor-level access and above, to delete arbitrary users, including Administrators.
CVSS 8.1EPSS 0.328%Risco 0.83
Ver fonte- Publicação
- 2026-05-02 14:16:17
- Versões afetadas
- <=6.7.25
- Tipo
- Installed app
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H