CyberRota Analysis
AI-GeneratedThe WCFM Marketplace plugin for WordPress, prior to version 3.8.1, lacks proper verification of vendor ownership for reviews, enabling any vendor to unapprove or delete reviews associated with other vendors' stores. This vulnerability could lead to reputational damage and manipulation of marketplace feedback, making it critical for WordPress site administrators using this plugin to prioritize an update to mitigate potential abuse.
Original NVD Description
The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, allowing any vendor to modify or permanently delete reviews belonging to other vendors' stores.