CVE-2026-83562: WordPress WCFM Marketplace plugin <= 3.8.2 - Cross Site Scripting (XSS) vulnerability
Published Sep 2, 2026
·Updated
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
Affected Software
1 affected component
WordPress WCFM Marketplace<=3.8.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WCFM Marketplace pluginto a version that resolves this vulnerability.Fixed in 3.8.3
Event History
Sep 2, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs contributor-level privileges in a WordPress site using an affected WCFM Marketplace version. Exploitation also requires a victim to interact with attacker-controlled content.
2
What is the potential impact?
Successful exploitation can run cross-site scripting payloads in another user's browser. The supplied vector indicates low-impact effects on confidentiality, integrity, and availability, with scope changed.
3
Which versions are affected?
WCFM Marketplace versions 3.8.2 and earlier are identified as affected by the available data.