CVE-2026-77701
WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.
| Vendor | unknown |
| Product | wcfm marketplace |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wcfm marketplace
Be the first to know when new unknown vulnerabilities affecting unknown wcfm marketplace are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WCFM Marketplace
3.7.1 < 3.8.2
References
Credits
Shikhali Jamalzade WPScan