CVE-2026-14196
Received Received - Intake

Unauthorized Review Deletion in WCFM Marketplace WordPress Plugin

Vulnerability report for CVE-2026-14196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: WPScan

Description

The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, allowing any vendor to modify or permanently delete reviews belonging to other vendors' stores.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wcfm wcfm_marketplace to 3.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) vulnerability in the WCFM Marketplace WordPress plugin before version 3.8.1. It allows any marketplace vendor to delete or modify reviews belonging to other vendors' stores without proper authorization because the plugin fails to verify review ownership before allowing actions like unapproving or deleting reviews.

Detection Guidance

Check the installed version of the WCFM Marketplace plugin in WordPress. If it is below 3.8.1, the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the version.

Impact Analysis

If you are a vendor using the WCFM Marketplace plugin, an attacker could delete or alter your store's reviews, damaging your reputation. Customers might see incorrect or missing reviews, leading to loss of trust and potential business impact.

Mitigation Strategies

Update the WCFM Marketplace plugin to version 3.8.1 or later immediately. Disable the plugin temporarily if an update is not immediately available, but ensure to update as soon as possible to avoid functionality loss.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart