CVE-2026-14196: WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR
The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, allowing any vendor to modify or permanently delete reviews belonging to other vendors' stores.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WCFM Marketplace WordPress pluginto a version that resolves this vulnerability.Fixed in 3.8.1
Event History
Frequently Asked Questions
Who can exploit this issue?
A marketplace vendor account can exploit the issue. The vulnerable authorization check allows one vendor to act on reviews belonging to other vendors' stores.
What actions can an attacker perform against another vendor's reviews?
An attacker can change a review's approval status or permanently delete it. The issue affects reviews that the attacking vendor does not own.
Which plugin versions are affected?
WCFM Marketplace versions before 3.8.1 are affected. Updating to version 3.8.1 or later addresses the affected version range.