CVE-2026-81286
moderate1Unauthenticated SQL Injection in WCFM Marketplace ≤ 3.8.1
CVE-2026-81286 is a critical unauthenticated SQL injection (CWE-89) in the WCFM Marketplace multi-vendor plugin for WordPress, affecting versions 3.8.1 and earlier. An attacker with no account or privileges can trigger the flaw by sending a crafted HTTP request to an exposed plugin endpoint, where unsanitized input is executed as part of a database query. The CVSS score of 9.3 with a changed scope and high confidentiality impact indicates the attacker can read sensitive database contents beyond the plugin's own data, potentially including user credentials and marketplace records, with only limited availability impact. Any WordPress site running WCFM Marketplace 3.8.1 or older is affected, and multi-vendor WooCommerce marketplace sites are the primary deployments. There is no known public proof of concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, so no confirmed in-the-wild exploitation is documented yet.
What to do: Update WCFM Marketplace to the latest available version above 3.8.1 as soon as possible; if immediate patching is not possible, temporarily deactivate the plugin or apply a WAF/virtual-patch rule for SQL injection. Review web-server and database logs for anomalous or unexpected queries, and audit user accounts for signs of credential exposure.
| WC Lovers WCFM Marketplace (WordPress plugin) | <= 3.8.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.