WCFM – Frontend Manager for WooCommerce
wc-frontend-manager · plugin
Known security vulnerabilities for WCFM – Frontend Manager for WooCommerce. Find out in seconds which version runs on your site with WP Lens.
11 known vulnerabilities
latest Jul 11, 2026
Vulnerabilities
- High 8.8
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Pr
- High 8.8
WCFM Frontend Manager <= 6.5.13 - Cross-Site Request Forgery
- High 8.8
The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and includin
- High 8.1
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Referenc
- High 8.1
WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation
- High 7.2
WCFM - WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary Options Update
- Medium 6.5
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Setting
- Medium 5.9
WordPress WCFM plugin <= 6.7.8 - Cross Site Scripting (XSS) vulnerability
- Medium 5.3
WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manag
- Medium 4.3
WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Ha
- Low 2.7
WordPress WCFM – Frontend Manager for WooCommerce plugin <= 6.7.24 - Broken Access Control vulnerability