๐Ÿ” CVE Alert

CVE-2026-77701

UNKNOWN 0.0

WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.

Vendor unknown
Product wcfm marketplace
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wcfm marketplace

Be the first to know when new unknown vulnerabilities affecting unknown wcfm marketplace are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WCFM Marketplace
3.7.1 < 3.8.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/38195936-5dc2-474f-84e5-fdcc0b39caca/

Credits

Shikhali Jamalzade WPScan