CVE-2026-81286: WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability
Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WCFM Marketplace pluginto a version that resolves this vulnerability.Fixed in 3.8.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or marketplace vendor privileges to attempt exploitation. The network attack vector and low attack complexity indicate it can be targeted remotely with little setup.
Which installations are affected?
WCFM Marketplace plugin versions 3.8.1 and earlier are identified as affected. The provided information does not state whether any particular WordPress or plugin configuration avoids exposure.
What is the likely impact of successful exploitation?
Successful exploitation can expose highly sensitive information and affect resources beyond the vulnerable component's security scope. The supplied vector indicates no integrity impact and low availability impact.