Executive brief
WCFM Membership is a WordPress plugin that manages vendor memberships and access control for WooCommerce multivendor marketplaces. The plugin contains a broken access control vulnerability that allows unauthenticated users to access pages and perform actions they should not be permitted to, potentially exposing sensitive vendor or customer data.
Technical details
This is a broken access control vulnerability (OWASP A1) in WCFM Membership that allows users to bypass authorization checks and access restricted pages or perform unauthorized actions. The vulnerability affects versions up to 2.11.11 and requires no authentication to exploit. An attacker can access pages or perform operations intended for other users or higher-privilege accounts, potentially exposing confidential business or customer information. The vulnerability was patched in version 2.12.0.
Affected products
- WC Lovers WCFM Membership through 2.11.11
Timeline
- 2026-06-19: disclosed: Reported by mySebbe
- 2026-09-04: advisory: Published by Patchstack
- 2026-09-04: patched: Fixed in version 2.12.0