Junglewise Threat Intelligence

CVE-2026-84756: WCFM Membership privilege escalation

CVE-2026-84756 · Severity: high · CVSS 7.1 · Published 2026-09-03

Technologies: WC Lovers WCFM Membership. Vendors: WC Lovers.

Executive brief

WCFM Membership is a WordPress plugin that manages vendor memberships and access for WooCommerce multivendor marketplaces. A low-privilege subscriber user can escalate their account to administrator, gaining full control over the WordPress site, including access to sensitive business data, customer information, and the ability to modify site content or inject malware.

Technical details

This vulnerability is a privilege escalation flaw in WCFM Membership plugin versions up to 2.11.11. A subscriber-level user can exploit an authentication or authorization bypass to elevate their privileges to administrator without proper access controls. The vulnerability requires only subscriber-level access to trigger and can be exploited remotely by an authenticated attacker. Full details of the vulnerable component or attack mechanism are not disclosed in the advisory. The issue has been patched in version 2.12.0.

Affected products

  • WC Lovers WCFM Membership <=2.11.11

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: Fixed in version 2.12.0
  • 2026-06-21: other: Reported by yagamimoon

References

Related threats