CVE-2026-81428: WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modification via IDOR
The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users with the vendor role to modify product variations belonging to other vendors, and to change the status and title of arbitrary posts, via IDOR.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with the WC Vendors vendor role can exploit it. The issue affects sites using WC Vendors versions before 2.7.2.1.
What can an attacker modify?
A vendor can modify product variations belonging to other vendors. They can also change the title and status of arbitrary posts by supplying IDs that are not validated for ownership or object type.
How can I determine whether my site is affected?
Check the installed WC Vendors plugin version. Versions earlier than 2.7.2.1 are affected; review changes to product variations and unexpected title or status changes on posts for signs of misuse.