
CVE-2026-12126 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all ve… https://www.cve.org/CVERecord?id=CVE-2026-12126
Post summary
The text provides a brief disclosure of CVE-2026-12126, noting a stored XSS vulnerability in the WCFM Marketplace WooCommerce plugin via the 'post_title' attachment field.
