What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows SQL Injection.This issue affects WCFM Marketplace: from n/a through <= 3.7.1.
Explanation of Vulnerability in Simple Terms
02Summary
WCFM Marketplace versions up to 3.7.1 contain a SQL injection vulnerability in a high-privilege function. An authenticated admin or vendor with elevated permissions can craft malicious input to read sensitive database records, including user credentials and site configuration. The vulnerability requires admin-level access and does not allow data modification or site takeover, but exposes confidential information across the marketplace.
What an attacker can do
03Attacker Capabilities
Read sensitive database records, including user credentials and site configuration data.
Potential impact on your site
04Site Impact
Vendor and customer data, including passwords and personal information, may be exposed to privileged insiders.
Conditions required to exploit
05Prerequisites
Attacker must have admin or high-privilege vendor account on the marketplace.
Key dates
06Disclosure timeline
April 15, 2026
CVE published
April 28, 2026
Record updated