---
id: CVE-2026-4896
title: >-
  The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription
  Listings Compatible plugin for WordPress is vulnerable to Insecure Direct
  Object Reference in all versions up to, and including, 6.7.25 via multiple
  AJAX action…
summary: >-
  The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription
  Listings Compatible plugin for WordPress is vulnerable to Insecure Direct
  Object Reference in all versions up to, and including, 6.7.25 via multiple
  AJAX action…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-639
published: '2026-04-04'
updated: '2026-07-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4896'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.24/core/class-wcfm-ajax.php?marks=644,880#L644
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.24/core/class-wcfm-article.php?marks=271#L271
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/f8248098-dff2-4bac-a138-aa40c7ab7a1c?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00351
epssPercentile: 0.28789
ingestedAt: '2026-07-21T19:53:39.805Z'
---

## Overview

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`, `delete_wcfm_product`, and the article management controller due to missing validation on user-supplied object IDs. This makes it possible for authenticated attackers, with Vendor-level access and above, to modify the status of any order, delete or modify any post/product/page, regardless of ownership.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
