CVE-2026-77701: WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders
Published Aug 28, 2026
·Updated
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.
Affected Software
1 affected component
WordPress plugin WCFM Marketplace<3.8.2
Event History
Aug 28, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Does an attacker need a WordPress account or customer login?
No. Unauthenticated users can create refund requests for guest checkout orders.
2
Which sites are exposed to this issue?
Sites using WCFM Marketplace versions earlier than 3.8.2 that have guest checkout orders are affected.
3
What version resolves the issue?
Upgrade WCFM Marketplace to version 3.8.2 or later.