CVE-2026-10041

MEDIUM

CVSS v3.1: 4.3 · EPSS: 0.0025 (16.3 percentile)

NetworkNo user interactionAuthorization Bypass (IDOR)

Source data as of:

At a glance

Severity
MEDIUM
CVSS
4.3 v3.1 · NVD
EPSS
0.0025 (16.3 percentile) · FIRST.org
CISA KEV
No
Type
Authorization Bypass (IDOR) · NVD CWE
Attack conditions (CVSS vector)
NetworkNo user interaction · Source: NVD Vector
Published
2026-07-11 · Modified: 2026-07-11

CVSS / EPSS / KEV

CVSS v3.1 4.3 / 10 MEDIUM Source: NVD
EPSS 0.0025 16.3 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to archive arbitrary vendors' products, toggle the featured status on arbitrary listings, mark arbitrary WooCommerce orders as completed, and permanently delete arbitrary enquiries and bulk messages belonging to other vendors.

Record details

CVE ID
CVE-2026-10041
CVSS (v3.1)
4.3 (MEDIUM)
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability subscore
2.8
Impact subscore
1.4
EPSS
0.0025 (16.3 percentile) — 2026-07-12
CISA KEV
No
Weakness (CWE)
CWE-639
Affected configurations (CPE)
0
Published
2026-07-11
Modified
2026-07-11
Status
Received

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.