AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-3688

HIGH · CVSS 8.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The WCFM Membership plugin for WordPress is susceptible to an Insecure Direct Object Reference vulnerability that allows authenticated attackers with vendor-level access to alter any user's role to 'wcfm_vendor' by manipulating their membership plan. This could lead to unauthorized access and privilege escalation within the platform. WordPress site administrators and users of the affected plugin should prioritize applying updates to mitigate this high-severity risk.

CVE
CVE-2026-3688
Severity
HIGH
CVSS
8.1
EPSS
0.22%
WordPress

Original NVD Description

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.