CVE-2026-4896Disclosure

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`, `delete_wcfm_product`, and the article management controller due to missing validation on user-supplied object IDs. This makes it possible for authenticated attackers, with Vendor-level access and above, to modify the status of any order, delete or modify any post/product/page, regardless of ownership.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-04); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-04: 3Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-10: 1Technical Details · 2026-04-04: 304-0404-10
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-043
Disclosure2General1
2026-04-101
PoC1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4896 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference … https://www.cve.org/CVERecord?id=CVE-2026-4896

    Post summary

    The post announces CVE-2026-4896 as an Insecure Direct Object Reference flaw affecting the WCFM WooCommerce plugin and its companion, but offers no additional actionable details.

    00010167
    57.0K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4896-wc-frontend-manager-version-6-7-25-high-vulnerability-proof-of-concept CVE-2026-4896 #WordPress plugin #vulnerability wc-frontend-manager #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post links to a page claiming to host a proof‑of‑concept for CVE‑2026‑4896 in the WC Frontend Manager plugin, with no other exploit details or mitigation information.

    0000045
    6 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4896 - WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation Intel Report: https://ift.tt/qFIyzh7

    Post summary

    The tweet announces CVE‑2026‑4896 affecting WooCommerce Frontend Manager (WCFM) versions up to 6.7.25, highlighting insecure direct object references that allow authenticated vendors to arbitrarily manipulate posts or products, but provides no PoC, exploit, or patch details.

    0000061
    281 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-4896 - High The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,... https://www.thehackerwire.com/vulnerability/CVE-2026-4896/ https://t.co/3fWtT7dlnA

    Post summary

    The tweet announces CVE-2026-4896, indicating that WCFM and Bookings Subscription Listings plugins are vulnerable to an insecure direct object reference. No specific exploit, PoC, or mitigation details are included.

    0000047
    164 followersView on X

Explore more