Junglewise Threat Intelligence

CVE-2026-12994: wclovers WCFM Frontend Manager for WooCommerce authorization bypass

CVE-2026-12994 · Severity: medium · CVSS 5.3 · Published 2026-07-11

Technologies: WC Lovers WCFM - Frontend Manager for WooCommerce. Vendors: WC Lovers.

Executive brief

A vulnerability in the WCFM Frontend Manager plugin for WooCommerce allows unauthorized individuals to interfere with store inquiries. Attackers can inject fake replies into customer support threads and trigger unwanted notification emails to both vendors and customers. This could lead to misinformation, reputational damage, and disruption of customer service operations.

Technical details

The WCFM – Frontend Manager for WooCommerce plugin for WordPress contains a missing authorization vulnerability (CWE-862) in the wcfm-my-account-enquiry-manage controller branch. Unlike other inquiry controllers, this specific branch fails to implement is_user_logged_in() or current_user_can() checks. Furthermore, the security nonce used for validation is exposed on public page loads, allowing unauthenticated network attackers to bypass the only existing barrier. Exploitation allows an attacker to overwrite inquiry records in the wp_wcfm_enquiries table, inject arbitrary reply content, and trigger automated notification emails.

Affected products

  • wclovers WCFM – Frontend Manager for WooCommerce <= 6.7.27

Timeline

  • 2026-07-11: disclosed: Initial publication of the CVE record.

References

Related threats