WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

Information

Software Type Plugin
Software Slug wc-multivendor-membership (view on wordpress.org)
Software Status Active
Software Author wclovers
Software Website wclovers.com
Software Downloads 914,813
Software Active Installs 10,000
Software Record Last Updated August 11, 2026

7 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite Patched CVE-2026-3688 8.1 Osvaldo Noe Gonzalez Del Rio (Os) July 7, 2026
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.10 - Missing Authorization Patched CVE-2026-42753 5.3 0xzenko May 29, 2026
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecure Direct Object Reference to Update Membership Payment Patched CVE-2025-15147 4.3 Jing Xuan Sun February 9, 2026
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.10.7 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Password Change Patched CVE-2023-2276 9.8 István Márton May 3, 2023
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation Patched CVE-2022-4939 9.8 Chloe Chamberland April 5, 2023
WCFM Membership <= 2.10.0 - Missing Authorization Patched CVE-2022-4940 7.3 Chloe Chamberland April 5, 2023
WCFM Membership <= 2.9.10 - Cross-Site Request Forgery Patched CVE-2022-4941 6.3 Chloe Chamberland April 5, 2023

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation