Executive brief
The WCFM – Frontend Manager for WooCommerce plugin for WordPress, which allows vendors to manage their stores from the front end, contains a security flaw. This vulnerability allows any logged-in user, even those with low-level subscriber access, to interfere with other vendors' business operations. Specifically, an attacker could archive products, change listing statuses, mark orders as completed, or permanently delete customer inquiries and messages belonging to other sellers.
Technical details
The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) / Authorization Bypass through a User-Controlled Key (CWE-639). The vulnerability exists in the wcfm_product_archive function and related AJAX handlers due to a lack of proper validation on user-supplied identifiers. Authenticated attackers with subscriber-level permissions or higher can exploit this to perform unauthorized actions on objects belonging to other vendors. Impacted actions include archiving products, toggling 'featured' status, marking WooCommerce orders as completed, and permanently deleting enquiries or bulk messages. The issue affects all versions up to and including 6.7.27.
Affected products
- wclovers WCFM – Frontend Manager for WooCommerce up to, and including, 6.7.27
Timeline
- 2026-07-11: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-ajax.php
- https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-ajax.php
- https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-ajax.php
- https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-enquiry.php
- https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-notification.php
- https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-ajax.php
- https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-ajax.php