ZeroHour

CVE-2026-81286

moderate1

Unauthenticated SQL Injection in WCFM Marketplace ≤ 3.8.1

CVSS 3.1
9.3 critical
EPSS
<1%p22
Published
()
Modified
AI analysis

CVE-2026-81286 is a critical unauthenticated SQL injection (CWE-89) in the WCFM Marketplace multi-vendor plugin for WordPress, affecting versions 3.8.1 and earlier. An attacker with no account or privileges can trigger the flaw by sending a crafted HTTP request to an exposed plugin endpoint, where unsanitized input is executed as part of a database query. The CVSS score of 9.3 with a changed scope and high confidentiality impact indicates the attacker can read sensitive database contents beyond the plugin's own data, potentially including user credentials and marketplace records, with only limited availability impact. Any WordPress site running WCFM Marketplace 3.8.1 or older is affected, and multi-vendor WooCommerce marketplace sites are the primary deployments. There is no known public proof of concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, so no confirmed in-the-wild exploitation is documented yet.

What to do: Update WCFM Marketplace to the latest available version above 3.8.1 as soon as possible; if immediate patching is not possible, temporarily deactivate the plugin or apply a WAF/virtual-patch rule for SQL injection. Review web-server and database logs for anomalous or unexpected queries, and audit user accounts for signs of credential exposure.

Affected
WC Lovers WCFM Marketplace (WordPress plugin)<= 3.8.1
Estimated exposure
moderateon the order of tens of thousands of WordPress sites (plugin historically shows roughly 20,000–30,000 active installs on WordPress.org) — Estimate is based on the WCFM Marketplace plugin's WordPress.org active-install count (~20,000–30,000), which acts as an upper bound for vulnerable sites since the flaw is reachable over the network without authentication.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.

Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.