WCFM – Frontend Manager
cpe:2.3:a:wclovers:frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible:*:*:*:*:wordpress:*:*
- <= 6.7.25
A vulnerability exists in the WCFM – Frontend Manager for WooCommerce plugin, specifically in versions through 6.7.25, including the Bookings Subscription Listings Compatible plugin. The issue is an Insecure Direct Object Reference (IDOR) that allows authenticated attackers with Vendor-level access or higher to delete any user, including Administrators. This vulnerability arises from a lack of proper validation on the 'customerid' key, which is controlled by the user.
Exploitation of this vulnerability allows for the unauthorized deletion of users, including those with Administrator privileges.
Users are advised to update the WCFM Frontend Manager for WooCommerce plugin to version 6.7.26 or later.