---
id: CVE-2026-10041
title: >-
  The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable
  to Insecure Direct Object Reference in all versions up to, and including,
  6.7.27 via the wcfm_product_archive due to missing validation on a user
  controlled k…
summary: >-
  The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable
  to Insecure Direct Object Reference in all versions up to, and including,
  6.7.27 via the wcfm_product_archive due to missing validation on a user
  controlled k…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-639
published: '2026-07-11'
updated: '2026-07-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10041'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-ajax.php#L746
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-ajax.php#L779
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-ajax.php#L810
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-enquiry.php#L395
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-notification.php#L1132
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-ajax.php#L746
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-ajax.php#L779
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-ajax.php#L810
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-enquiry.php#L395
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-notification.php#L1132
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3588570%40wc-frontend-manager&new=3588570%40wc-frontend-manager
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/e3f88a18-5439-4759-ae9f-168f5efc3264?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00434
epssPercentile: 0.37242
ingestedAt: '2026-07-11T23:16:20.661Z'
---

## Overview

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to archive arbitrary vendors' products, toggle the featured status on arbitrary listings, mark arbitrary WooCommerce orders as completed, and permanently delete arbitrary enquiries and bulk messages belonging to other vendors.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
