High 7.6 Unfixed
2026-04-15≤ 3.7.1
WordPress WCFM Marketplace plugin <= 3.7.1 - SQL Injection vulnerability
Minimum safe version
3.7.1
Update to 3.7.1 or later to address 6 fixable vulnerabilities
WordPress WCFM Marketplace plugin <= 3.7.1 - SQL Injection vulnerability
WCFM Marketplace <= 3.7.0 - Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request Creation
CVE-2025-64631
CVE-2024-44009
CVE-2023-4960
WordPress WCFM Marketplace Plugin <= 3.4.11 is vulnerable to Broken Access Control
WordPress WCFM Marketplace Plugin <= 3.4.12 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2021-24849