The WCFM Marketplace WordPress plugin before 3.8.2 does...
Moderate severity
Unreviewed
Published
Aug 28, 2026
to the GitHub Advisory Database
•
Updated Aug 28, 2026
Description
Published by the National Vulnerability Database
Aug 28, 2026
Published to the GitHub Advisory Database
Aug 28, 2026
Last updated
Aug 28, 2026
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.
References