Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-81286: WCFM Marketplace plugin can let attackers change your data

CVE-2026-81286 · published 27 days ago
Summary

The WCFM Marketplace add‑on for WordPress up to version 3.8.1 lets anyone send specially crafted requests that modify the site’s database. This could let an attacker view, change or delete information without logging in. Update the plugin to the latest version or remove it if you do not need it.

What to do
  • Update wc lovers wcfm marketplace to version 3.8.2.
Affected software
VendorProductAffected versions
wc lovers wcfm marketplace <= 3.8.1
Fix: upgrade to 3.8.2
Original advisory text
WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability
Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
Severity
9.3 Critical
CVSS 3.1: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published2 Sep 2026
Updated27 Sep 2026
First seen2 Sep 2026
Sources
CVE-2026-81286 · MITRE
Track software like this
Free during beta