The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via the 'wcfm_delete_wcfm_customer' due to missing validation on the 'customerid' user controlled key. This makes it possible for authenticated attackers, with Vendor-level access and above, to delete arbitrary users, including Administrators.
Metrics
Affected Vendors & Products
References
History
Sat, 02 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wclovers
Wclovers wcfm – Frontend Manager For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Wclovers
Wclovers wcfm – Frontend Manager For Woocommerce Wordpress Wordpress wordpress |
Sat, 02 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via the 'wcfm_delete_wcfm_customer' due to missing validation on the 'customerid' user controlled key. This makes it possible for authenticated attackers, with Vendor-level access and above, to delete arbitrary users, including Administrators. | |
| Title | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-02T13:26:09.653Z
Reserved: 2026-02-15T17:16:55.850Z
Link: CVE-2026-2554
No data.
Status : Received
Published: 2026-05-02T14:16:17.707
Modified: 2026-05-02T14:16:17.707
Link: CVE-2026-2554
No data.
OpenCVE Enrichment
Updated: 2026-05-02T15:15:25Z