The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via the 'wcfm_delete_wcfm_customer' due to missing validation on the 'customerid' user controlled key. This makes it possible for authenticated attackers, with Vendor-level access and above, to delete arbitrary users, including Administrators.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 02 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wclovers
Wclovers wcfm – Frontend Manager For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Wclovers
Wclovers wcfm – Frontend Manager For Woocommerce Wordpress Wordpress wordpress |
Sat, 02 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via the 'wcfm_delete_wcfm_customer' due to missing validation on the 'customerid' user controlled key. This makes it possible for authenticated attackers, with Vendor-level access and above, to delete arbitrary users, including Administrators. | |
| Title | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-02T13:26:09.653Z
Reserved: 2026-02-15T17:16:55.850Z
Link: CVE-2026-2554
No data.
Status : Received
Published: 2026-05-02T14:16:17.707
Modified: 2026-05-02T14:16:17.707
Link: CVE-2026-2554
No data.
OpenCVE Enrichment
Updated: 2026-05-02T15:15:25Z
Weaknesses