Skip to content
Noroxi

WCFM – Frontend Manager for WooCommerce

wc-frontend-manager · plugin

Known security vulnerabilities for WCFM – Frontend Manager for WooCommerce. Find out in seconds which version runs on your site with WP Lens.

11 known vulnerabilities

latest Jul 11, 2026

Vulnerabilities

  • CVE-2024-8290

    WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Pr

    High 8.8
  • CVE-2022-4938

    WCFM Frontend Manager <= 6.5.13 - Cross-Site Request Forgery

    High 8.8
  • CVE-2022-4937

    The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and includin

    High 8.8
  • CVE-2026-2554

    WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Referenc

    High 8.1
  • CVE-2026-4896

    WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation

    High 8.1
  • CVE-2026-0845

    WCFM - WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary Options Update

    High 7.2
  • CVE-2025-3780

    WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Setting

    Medium 6.5
  • CVE-2024-29929

    WordPress WCFM plugin <= 6.7.8 - Cross Site Scripting (XSS) vulnerability

    Medium 5.9
  • CVE-2026-12994

    WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manag

    Medium 5.3
  • CVE-2026-10041

    WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Ha

    Medium 4.3
  • CVE-2025-54004

    WordPress WCFM – Frontend Manager for WooCommerce plugin <= 6.7.24 - Broken Access Control vulnerability

    Low 2.7

← Back to directory