Skip to main content
Vulnerability Database/CVE-2026-77701

CVE-2026-77701: WCFM Marketplace Auth Bypass Vulnerability

CVE-2026-77701 is an authentication bypass flaw in WCFM Marketplace WordPress plugin that allows unauthenticated attackers to create fraudulent refund requests against guest orders. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-77701 Overview

CVE-2026-77701 affects the WCFM Marketplace WordPress plugin in versions prior to 3.8.2. The plugin fails to verify that a user requesting a refund actually owns the associated order. Unauthenticated attackers can submit refund requests against any guest checkout order on a vulnerable site. The flaw maps to CWE-862: Missing Authorization and enables tampering with merchant order workflows without requiring credentials.

Critical Impact

Unauthenticated attackers can create refund requests against arbitrary guest checkout orders, disrupting order integrity and merchant operations on WordPress marketplaces running WCFM Marketplace before 3.8.2.

Affected Products

  • WCFM Marketplace WordPress plugin versions before 3.8.2
  • WordPress sites running WCFM Marketplace with guest checkout enabled
  • WooCommerce-based multivendor marketplaces built on WCFM

Discovery Timeline

  • 2026-08-28 - CVE-2026-77701 published to NVD
  • 2026-08-28 - Last updated in NVD database

Technical Details for CVE-2026-77701

Vulnerability Analysis

The WCFM Marketplace plugin exposes a refund request workflow accessible without authentication. The endpoint accepts an order identifier and creates a refund request tied to that order. The plugin does not confirm that the requester owns the order or holds a session bound to it. An attacker who can enumerate or guess guest order identifiers can submit refund requests against orders belonging to other customers.

Because guest checkouts do not require a customer account, the vendor-side code relies solely on the order identifier as an implicit authorization token. This design decision allows any network-based attacker to interact with the refund workflow. The result is unauthorized modification of order state, notifications to vendors, and potential disruption to legitimate refund handling.

Root Cause

The root cause is missing authorization on the refund request handler. The plugin does not validate the caller against the order owner or a valid guest session token before creating a refund entry. This is a classic broken access control pattern in which an object reference is treated as sufficient proof of ownership.

Attack Vector

Exploitation requires only network access to the target WordPress site. An attacker sends a crafted HTTP request to the refund request endpoint referencing a guest order identifier. No authentication, user interaction, or elevated privileges are required. Consult the WPScan Vulnerability Report for endpoint specifics and reproduction details.

Detection Methods for CVE-2026-77701

Indicators of Compromise

  • Unexpected refund request records in the WCFM Marketplace database tied to guest orders.
  • Vendor notifications about refund requests that customers did not initiate.
  • Spikes in POST requests to WCFM refund-related endpoints from a small set of source IP addresses.

Detection Strategies

  • Review WCFM refund logs and correlate refund creation timestamps with customer-initiated activity or session data.
  • Inspect webserver access logs for repeated requests to WCFM refund endpoints, especially with sequential or enumerated order IDs.
  • Alert on refund requests created without an authenticated WordPress session cookie present in the originating request.

Monitoring Recommendations

  • Enable verbose logging on the WooCommerce and WCFM order and refund subsystems.
  • Monitor for anomalous increases in refund request volume across vendors.
  • Forward WordPress and web server logs to a centralized analytics platform for correlation and retention.

How to Mitigate CVE-2026-77701

Immediate Actions Required

  • Upgrade the WCFM Marketplace plugin to version 3.8.2 or later on all affected WordPress sites.
  • Audit refund request records created before the upgrade to identify unauthorized entries.
  • Notify vendors and affected guest customers if unauthorized refund requests are found.

Patch Information

The vendor addressed CVE-2026-77701 in WCFM Marketplace version 3.8.2. The fix introduces ownership verification on refund requests so that only the original purchaser, or an authenticated session bound to the guest order, can submit a refund. Refer to the WPScan Vulnerability Report for confirmation of the fixed version.

Workarounds

  • Disable guest checkout on WooCommerce until the plugin is patched, forcing account-based purchases with authenticated refund requests.
  • Apply web application firewall rules to block unauthenticated access to WCFM refund request endpoints.
  • Restrict access to WCFM refund URLs by IP allowlist where operationally feasible until the upgrade is completed.
bash
# Configuration example: temporarily block unauthenticated access to WCFM refund endpoints via WAF/nginx
location ~* /wcfm/.*refund {
    if ($http_cookie !~ "wordpress_logged_in") {
        return 403;
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.