CVE-2026-2554
WCFM – Frontend Manager for WooCommerce
Minimum safe version
6.7.26
Update to 6.7.26 or later to address 11 fixable vulnerabilities
WCFM - WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary Options Update
WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation
CVE-2025-54004
WordPress WCFM – Frontend Manager for WooCommerce Plugin <= 6.7.16 is vulnerable to Broken Access Control
CVE-2024-8290
CVE-2024-29929
WordPress WCFM – Frontend Manager for WooCommerce Plugin 6.6.0 is vulnerable to Broken Access Control
WordPress WCFM – Frontend Manager for WooCommerce Plugin <= 6.5.13 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress WCFM – Frontend Manager for WooCommerce plugin <= 6.6.1 - Unauthenticated SQL Injection (SQLi) vulnerability
CVE-2021-24835