WCFM WooCommerce Frontend Manager Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object References (IDOR) has been identified in the WCFM - Frontend Manager for WooCommerce plugin, specifically in versions through 6.7.25. This vulnerability arises from missing validation on user-supplied object IDs in several AJAX actions, including 'wcfm_modify_order_status', 'delete_wcfm_article', 'delete_wcfm_product', and the article management controller. As a result, authenticated attackers with Vendor-level access or higher can manipulate the status of any order or delete and modify any post, product, or page, regardless of ownership.

Impact

Exploitation of this vulnerability allows for arbitrary manipulation of posts, products, and pages, as well as unauthorized changes to order statuses.

Reproduction

To reproduce this vulnerability, an authenticated user with Vendor-level access or higher can send AJAX requests to the WordPress site. The requests must include the 'wcfm_modify_order_status', 'delete_wcfm_article', or 'delete_wcfm_product' actions. The absence of proper validation on the object IDs provided by the user allows for the manipulation of orders and content ownership.

Remediation

Users are advised to update the WCFM - Frontend Manager for WooCommerce plugin to version 6.7.26 or a newer patched version.

Added: Apr 4, 2026, 8:19 AM
Updated: Apr 4, 2026, 8:19 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
6.4
remediation
7.7
relevance
4.9
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.