Junglewise Threat Intelligence

CVE-2026-42753: WC Lovers WCFM Membership missing authorization

CVE-2026-42753 · Severity: high · CVSS 7.3 · Published 2026-05-27

Technologies: WC Lovers WCFM Membership. Vendors: WC Lovers.

Executive brief

A security flaw has been identified in the WCFM Membership plugin, which is used to manage vendor subscriptions and memberships on WordPress-based e-commerce sites. This vulnerability allows unauthorized individuals to bypass intended access restrictions due to incorrectly configured security levels. An attacker could potentially access or modify data they should not have permission to see, impacting the integrity and privacy of the membership system.

Technical details

The WCFM Membership plugin for WordPress is vulnerable to missing authorization (CWE-862) in versions up to and including 2.11.10. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions for certain actions or data. A remote, unauthenticated attacker can exploit this over the network to bypass security restrictions. This could lead to unauthorized access to sensitive membership information or the ability to perform restricted administrative tasks. Users are advised to update to a version higher than 2.11.10 if available.

Affected products

  • WC Lovers WCFM Membership (wc-multivendor-membership) <= 2.11.10

Timeline

  • 2026-05-27: disclosed: Initial publication of the CVE record.
  • 2026-05-27: advisory: Advisory published by Patchstack.

References

Related threats