
CVE-2026-12994 The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. This is due to th… https://www.cve.org/CVERecord?id=CVE-2026-12994
Post summary
CVE-2026-12994 reveals an authorization bypass in the WCFM – Frontend Manager plugin for WooCommerce, impacting all plugin versions up to 6.7.27. The vulnerability is documented but no exploitation or mitigation details are provided.
