
CryptoCat@_CryptoCat
Found an SQL injection in WCFM Marketplace, the WooCommerce multivendor plugin. A guest's checkout coordinates flow straight into a store-distance query, enough to read WordPress password hashes. CVE-2026-18442, fixed in 3.8.2, $134 bounty. https://cryptocat.me/blog/research/analysis/cve_2026_18442/
00072347
9.0K followersView on X
