CVE-2026-4896 Details
Description
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`, `delete_wcfm_product`, and the article management controller due to missing validation on user-supplied object IDs. This makes it possible for authenticated attackers, with Vendor-level access and above, to modify the status of any order, delete or modify any post/product/page, regardless of ownership.
A vulnerability allowing Insecure Direct Object References (IDOR) has been identified in the WCFM - Frontend Manager for WooCommerce plugin, specifically in versions through 6.7.25. This vulnerability arises from missing validation on user-supplied object IDs in several AJAX actions, including 'wcfm_modify_order_status', 'delete_wcfm_article', 'delete_wcfm_product', and the article management controller. As a result, authenticated attackers with Vendor-level access or higher can manipulate the status of any order or delete and modify any post, product, or page, regardless of ownership.
Users are advised to update the WCFM - Frontend Manager for WooCommerce plugin to version 6.7.26 or a newer patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 4, 2026CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WCFM - WooCommerce Frontend Manager | <= 6.7.25 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 4, 2026 | New CVE Received | [email protected] |
Volerion