Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible MEDIUM 6.5
CVE-2025-3780

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized m…

Fix: 6.7.17+
Fix from $1,600 2025-07-09
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible HIGH 8.8
CVE-2024-8290

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direc…

Fix: 6.7.13+
Fix from $1,950 2024-09-25
Wcfm Marketplace MEDIUM 6.1
CVE-2024-44009

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marke…

Fix: after 3.6.11
Fix from $1,600 2024-09-17
Wcfm Marketplace MEDIUM 5.4
CVE-2023-4960

The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in versions up to, and including, …

Fix: after 3.6.2
Fix from $1,600 2024-01-11
Woocommerce Multivendor Marketplace MEDIUM 5.4
CVE-2023-2275

The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a mi…

Fix: after 1.5.3
Fix from $1,600 2023-06-09
Wcfm Membership CRITICAL 9.8
CVE-2023-2276

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in …

Fix: after 2.10.7
Fix from $2,300 2023-05-20
Wcfm Membership CRITICAL 9.8
CVE-2022-4939

THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability c…

Fix: 2.10.1+
Fix from $2,300 2023-04-05
Wcfm Membership HIGH 8.8
CVE-2022-4941

The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10 due to missing nonce ch…

Fix: 2.10.0+
Fix from $1,950 2023-04-05
Wcfm Membership MEDIUM 6.5
CVE-2022-4940

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due t…

Fix: 2.10.11+
Fix from $1,600 2023-04-05
Wcfm Marketplace HIGH 8.8
CVE-2022-4935

The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due …

Fix: 3.4.12+
Fix from $1,950 2023-04-05
Wcfm Marketplace HIGH 8.8
CVE-2022-4936

The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce c…

Fix: 3.4.12+
Fix from $1,950 2023-04-05
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible HIGH 8.8
CVE-2022-4937

The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 …

Fix: 6.6.1+
Fix from $1,950 2023-04-05
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible HIGH 8.8
CVE-2022-4938

The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing non…

Fix: after 6.5.13
Fix from $1,950 2023-04-05
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible CRITICAL 9.8
CVE-2021-24849EPSS 8%

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, doe…

Fix: 3.4.12+
Fix from $2,300 2021-12-21
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible HIGH 8.8
CVE-2021-24835

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combina…

Fix: 6.5.12+
Fix from $1,950 2021-11-08