Executive brief
WCFM Marketplace is a WordPress plugin that enables multi-vendor e-commerce functionality on WordPress sites. An unauthenticated SQL injection vulnerability allows attackers to read, modify, or delete the entire database without needing any credentials, potentially exposing customer data, payment information, and user accounts.
Technical details
An unauthenticated SQL injection vulnerability exists in WCFM Marketplace versions up to 3.8.1 that allows attackers to execute arbitrary SQL queries against the application database. The vulnerability can be exploited by any unauthenticated attacker over the network without requiring user interaction or elevated privileges. Successful exploitation enables complete database compromise including reading sensitive data, modifying records, or deleting information. The vulnerability is fixed in version 3.8.2 and later.
Affected products
- WC Lovers WCFM Marketplace <= 3.8.1
Timeline
- 2026-09-02: disclosed: CVE-2026-81286 published
- 2026-09-01: patched: Fixed in version 3.8.2