Junglewise Threat Intelligence

CVE-2026-3688: WC Lovers WCFM Membership IDOR in wcfmvm_membership_change

CVE-2026-3688 · Severity: high · CVSS 8.1 · Published 2026-07-08

Technologies: WC Lovers WCFM Membership – WooCommerce Memberships for Multivendor Marketplace. Vendors: WC Lovers.

Executive brief

A vulnerability in the WCFM Membership plugin for WordPress allows users with vendor-level access to change the membership plans and roles of other users. This plugin is used to manage multi-vendor marketplaces, and this flaw could allow a vendor to inappropriately modify account permissions across the platform. This could lead to unauthorized access to vendor-only features or disruption of user account management.

Technical details

The vulnerability is classified as an Insecure Direct Object Reference (IDOR) within the 'wcfmvm_membership_change' AJAX action. The root cause is a lack of proper authorization validation, which fails to verify if the requesting user has the permission to modify the membership details of other users. An authenticated attacker with at least 'vendor' level permissions can exploit this by sending a crafted request to change another user's membership plan, effectively forcing their role to 'wcfm_vendor'. This issue affects all versions up to and including 2.11.10.

Affected products

  • WC Lovers WCFM Membership – WooCommerce Memberships for Multivendor Marketplace up to, and including, 2.11.10

Timeline

  • 2026-07-08: advisory: NVD and Wordfence published the vulnerability details.

References