CVE-2026-77701

Summary

The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.

Affected Software

VendorProductVersion RangeStatus
UnknownWCFM Marketplace3.7.1 < 3.8.2affected

Weaknesses

  • CWE-862 Missing Authorization

References