CyberRota Analysis
AI-GeneratedThe WCFM Marketplace plugin for WordPress prior to version 3.8.2 is vulnerable due to inadequate verification of refund requests, enabling unauthenticated users to submit refund claims for any guest checkout order. This flaw could lead to financial losses and unauthorized manipulation of order transactions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.