Junglewise Threat Intelligence

CVE-2026-83562: WCFM Marketplace contributor cross-site scripting

CVE-2026-83562 · Severity: medium · CVSS 6.5 · Published 2026-09-02

Technologies: WC Lovers WCFM Marketplace – Multivendor Marketplace for WooCommerce. Vendors: WC Lovers.

Executive brief

WCFM Marketplace is a WordPress plugin that enables multi-vendor marketplace functionality on WordPress sites. A contributor-level account holder can inject malicious scripts that execute in the browsers of site visitors or other users, potentially leading to account hijacking, session theft, or malware distribution.

Technical details

The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in WCFM Marketplace versions up to and including 3.8.2. The vulnerability requires a contributor-level user account to exploit, meaning an attacker must either possess legitimate credentials or compromise an existing contributor account. The XSS injection occurs through an unvalidated input field accessible to contributors. Successful exploitation allows injection of arbitrary JavaScript that executes in the context of other users' browsers, enabling session hijacking, credential theft, or malware delivery. The vulnerability has been patched in version 3.8.3 and later.

Affected products

  • WC Lovers WCFM Marketplace 3.8.2 and earlier

Timeline

  • 2026-07-13: disclosed: Reported by Ananda Dhakal to Patchstack
  • 2026-08-31: advisory: Published by Patchstack
  • 2026-08-31: patched: Fixed in version 3.8.3

References