Executive brief
A security flaw has been identified in the WCFM Membership plugin, which is used to manage vendor subscriptions and memberships on WordPress-based e-commerce sites. This vulnerability allows unauthorized individuals to bypass intended access restrictions due to incorrectly configured security levels. An attacker could potentially access or modify data they should not have permission to see, impacting the integrity and privacy of the membership system.
Technical details
The WCFM Membership plugin for WordPress is vulnerable to missing authorization (CWE-862) in versions up to and including 2.11.10. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions for certain actions or data. A remote, unauthenticated attacker can exploit this over the network to bypass security restrictions. This could lead to unauthorized access to sensitive membership information or the ability to perform restricted administrative tasks. Users are advised to update to a version higher than 2.11.10 if available.
Affected products
- WC Lovers WCFM Membership (wc-multivendor-membership) <= 2.11.10
Timeline
- 2026-05-27: disclosed: Initial publication of the CVE record.
- 2026-05-27: advisory: Advisory published by Patchstack.