CVE-2026-1722Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.0. This is due to the plugin not implementing authorization checks in the `wcfm-refund-requests-form` AJAX controller. This makes it possible for unauthenticated attackers to create arbitrary refund requests for any order ID and item ID, potentially leading to financial loss if automatic refund approval is enabled in the plugin settings.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-10: 3Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-10: 202-10
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1722 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi… https://www.cve.org/CVERecord?id=CVE-2026-1722

    Post summary

    The statement announces that the WCFM Marketplace plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to the time of the report, without providing additional technical details, exploits, or remediation advice.

    00010207
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1722 Unauthenticated Refund Request Injection in WCFM Marketplace WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1722

    Post summary

    The snippet simply announces CVE-2026-1722 as an unauthenticated refund request injection in the WCFM Marketplace WordPress plugin, providing no further details, PoC, or exploit information.

    0000049
    4.0K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    📌 #WooCommerce security alert: CVE-2026-1722 exposes an Insecure Direct Object Reference (IDOR) in the WCFM Marketplace – Multivendor Marketplace plugin (≤ 3.7.0). https://nvd.nist.gov/vuln/detail/CVE-2026-1722 This allows unauthenticated attackers to forge arbitrary refund requests for any order ID — leading to potential financial loss if auto-refunds are enabled. 🔧 Fix it: Update the plugin to a patched version that enforces authorization checks on refund endpoints. Always keep WooCommerce extensions current and audit permission logic. 🔒 Strengthen your store’s defenses with full perimeter security and proactive monitoring: https://quttera.com/website-anti-malware-monitoring #WooCommerce #WordPressSecurity #ecommerce #IDOR #CyberSecurity #Vulnerability #CVE #Malware

    Post summary

    The post announces a CVE‑2026‑1722 IDOR vulnerability in the WCFM Marketplace plugin and urges users to update to a patched version, providing basic technical details but no evidence of exploitation or a PoC.

    0000059
    37 followersView on X

Explore more