SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-14196

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The WCFM Marketplace plugin for WordPress, prior to version 3.8.1, lacks proper verification of vendor ownership for reviews, enabling any vendor to unapprove or delete reviews associated with other vendors' stores. This vulnerability could lead to reputational damage and manipulation of marketplace feedback, making it critical for WordPress site administrators using this plugin to prioritize an update to mitigate potential abuse.

CVE
CVE-2026-14196
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%
WordPress

Original NVD Description

The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, allowing any vendor to modify or permanently delete reviews belonging to other vendors' stores.