Known vulnerabilities in WCFM – Multivendor Marketplace REST API for WooCommerce
REST API for the most featured and powerful multi vendor plugin for your WooCommerce Multi-vendor Marketplace.
2Reported vulnerabilities
6.5Highest CVSS score
1.6.3Latest version
1,000+Active installs
What to do now
Update WCFM – Multivendor Marketplace REST API for WooCommerce to 1.6.3 or later.
2 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-1311 | Medium | 0.4% | 0 to 1.6.2 (inclusive) | 1.6.3 |
March 22, 2025 |
| CVE-2023-2275 | Medium | 0.5% | 1.5.3 and earlier | 1.6.0 |
June 9, 2023 |