
CVE-2026-10041 The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via th… https://www.cve.org/CVERecord?id=CVE-2026-10041
Post summary
A new vulnerability (CVE-2026-10041) has been disclosed in the WCFM Frontend Manager for WooCommerce plugin, identified as an Insecure Direct Object Reference affecting all versions up to 6.7.27.
