WordPress Plugin Vulnerabilities
WCFM - WooCommerce Multivendor Membership < 2.11.11 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite
Description
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.
Affects Plugins
References
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Osvaldo Noe Gonzalez Del Rio (Os)
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-07 (about 1 month ago)
Added
2026-07-08 (about 1 month ago)
Last Updated
2026-07-08 (about 1 month ago)