CVE-2026-0845Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'WCFM_Settings_Controller::processing' function in all versions up to, and including, 6.7.24. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-09); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-09: 1Mentions · 2026-02-10: 1Mentions · 2026-02-15: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-15: 102-0902-1002-15
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-101
Disclosure1
2026-02-151
General1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0845 WordPress WCFM Plugin Privilege Escalation via Unauthorized Settings Modi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0845 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces CVE-2026-0845, a privilege escalation flaw in the WordPress WCFM plugin that permits unauthorized setting modifications, and links to vulnerability details but offers no PoC, exploit, patch, or evidence of active exploitation.

    0001061
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0845 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data… https://www.cve.org/CVERecord?id=CVE-2026-0845

    Post summary

    The post announces a new CVE (CVE‑2026‑0845) affecting the WCFM WordPress plugin, noting it permits unauthorized data modification, but provides no PoC, exploit, patch, or evidence of active use.

    00010261
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-0845 (CVSS:7.2, HIGH) is Awaiting Analysis. The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is..https://nvd.nist.gov/vuln/detail/CVE-2026-0845 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-0845 with a high CVSS score and links to its NVD entry, but provides no PoC, exploit details, or patch information, indicating a general disclosure awaiting further analysis.

    0000026
    171 followersView on X

Explore more