Vulnerability in WCFM Marketplace – Multivendor Marketplace for WooCommerce — CVE-2026-83562
MediumSeverity
0.2%Estimated exploit probability
10,000+ sitesInstalls
3.8.3Fixed in
What to do now
Update WCFM Marketplace – Multivendor Marketplace for WooCommerce to 3.8.3 or later.
Affected versions
- Everything up to and including 3.8.2
Affected: WCFM Marketplace – Multivendor Marketplace for WooCommerce (plugin, wc-multivendor-marketplace)
What the vulnerability is
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.8.2. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.