Vendor
WC Lovers vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 11 vulnerabilities in WC Lovers: 0 in the last 7 days and 8 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-32480, was published on 4 September 2026. 3 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 8
- Critical, all time
- 1
- Exploited in the wild
- 0
About WC Lovers
WC Lovers is a software developer specializing in multi-vendor marketplace solutions and plugins for the WooCommerce platform.
WC Lovers technologies
Latest WC Lovers vulnerabilities
- CVE-2026-32480: WC Lovers WCFM Membership broken access control vulnerabilitymediumCVSS 5.3EPSS 0.3%
- CVE-2026-84756: WCFM Membership privilege escalationhighCVSS 7.1EPSS 0.3%
- CVE-2026-83562: WCFM Marketplace contributor cross-site scriptingmediumCVSS 6.5EPSS 0.2%
- CVE-2026-81286: WCFM Marketplace SQL injectioncriticalCVSS 9.3EPSS 0.4%
- CVE-2026-12994: wclovers WCFM Frontend Manager for WooCommerce authorization bypassmediumCVSS 5.3
- CVE-2026-12126: wclovers WCFM Marketplace Stored XSS in media attachment post_titlemediumCVSS 6.4
- CVE-2026-10041: wclovers WCFM Frontend Manager for WooCommerce IDOR in wcfm_product_archivemediumCVSS 4.3
- CVE-2026-3688: WC Lovers WCFM Membership IDOR in wcfmvm_membership_changehighCVSS 8.1
- CVE-2026-22335: WC Lovers WooCommerce Frontend Manager , Ultimate SQL injectionhighCVSS 8.5
- CVE-2026-42753: WC Lovers WCFM Membership missing authorizationhighCVSS 7.3
- CVE-2026-4896: wclovers WCFM Frontend Manager IDOR in AJAX actionshighCVSS 8.1EPSS 0.4%
Most severe WC Lovers vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-81286: WCFM Marketplace SQL injectioncriticalCVSS 9.3EPSS 0.4%
- CVE-2026-22335: WC Lovers WooCommerce Frontend Manager , Ultimate SQL injectionhighCVSS 8.5
- CVE-2026-4896: wclovers WCFM Frontend Manager IDOR in AJAX actionshighCVSS 8.1EPSS 0.4%
- CVE-2026-3688: WC Lovers WCFM Membership IDOR in wcfmvm_membership_changehighCVSS 8.1
- CVE-2026-42753: WC Lovers WCFM Membership missing authorizationhighCVSS 7.3
- CVE-2026-84756: WCFM Membership privilege escalationhighCVSS 7.1EPSS 0.3%
- CVE-2026-83562: WCFM Marketplace contributor cross-site scriptingmediumCVSS 6.5EPSS 0.2%
- CVE-2026-12126: wclovers WCFM Marketplace Stored XSS in media attachment post_titlemediumCVSS 6.4
- CVE-2026-32480: WC Lovers WCFM Membership broken access control vulnerabilitymediumCVSS 5.3EPSS 0.3%
- CVE-2026-12994: wclovers WCFM Frontend Manager for WooCommerce authorization bypassmediumCVSS 5.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 4 | 1 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/wc-lovers.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "WC Lovers vulnerabilities", https://junglewise.ai/threats/vendors/wc-lovers, 26 September 2026.