Junglewise Threat Intelligence

CVE-2026-81286: WCFM Marketplace SQL injection

CVE-2026-81286 · Severity: critical · CVSS 9.3 · Published 2026-09-02

Technologies: WC Lovers WCFM Marketplace – Multivendor Marketplace for WooCommerce. Vendors: WC Lovers.

Executive brief

WCFM Marketplace is a WordPress plugin that enables multi-vendor e-commerce functionality on WordPress sites. An unauthenticated SQL injection vulnerability allows attackers to read, modify, or delete the entire database without needing any credentials, potentially exposing customer data, payment information, and user accounts.

Technical details

An unauthenticated SQL injection vulnerability exists in WCFM Marketplace versions up to 3.8.1 that allows attackers to execute arbitrary SQL queries against the application database. The vulnerability can be exploited by any unauthenticated attacker over the network without requiring user interaction or elevated privileges. Successful exploitation enables complete database compromise including reading sensitive data, modifying records, or deleting information. The vulnerability is fixed in version 3.8.2 and later.

Affected products

  • WC Lovers WCFM Marketplace <= 3.8.1

Timeline

  • 2026-09-02: disclosed: CVE-2026-81286 published
  • 2026-09-01: patched: Fixed in version 3.8.2

References