CVE-2026-77701 Overview
CVE-2026-77701 affects the WCFM Marketplace WordPress plugin in versions prior to 3.8.2. The plugin fails to verify that a user requesting a refund actually owns the associated order. Unauthenticated attackers can submit refund requests against any guest checkout order on a vulnerable site. The flaw maps to CWE-862: Missing Authorization and enables tampering with merchant order workflows without requiring credentials.
Critical Impact
Unauthenticated attackers can create refund requests against arbitrary guest checkout orders, disrupting order integrity and merchant operations on WordPress marketplaces running WCFM Marketplace before 3.8.2.
Affected Products
- WCFM Marketplace WordPress plugin versions before 3.8.2
- WordPress sites running WCFM Marketplace with guest checkout enabled
- WooCommerce-based multivendor marketplaces built on WCFM
Discovery Timeline
- 2026-08-28 - CVE-2026-77701 published to NVD
- 2026-08-28 - Last updated in NVD database
Technical Details for CVE-2026-77701
Vulnerability Analysis
The WCFM Marketplace plugin exposes a refund request workflow accessible without authentication. The endpoint accepts an order identifier and creates a refund request tied to that order. The plugin does not confirm that the requester owns the order or holds a session bound to it. An attacker who can enumerate or guess guest order identifiers can submit refund requests against orders belonging to other customers.
Because guest checkouts do not require a customer account, the vendor-side code relies solely on the order identifier as an implicit authorization token. This design decision allows any network-based attacker to interact with the refund workflow. The result is unauthorized modification of order state, notifications to vendors, and potential disruption to legitimate refund handling.
Root Cause
The root cause is missing authorization on the refund request handler. The plugin does not validate the caller against the order owner or a valid guest session token before creating a refund entry. This is a classic broken access control pattern in which an object reference is treated as sufficient proof of ownership.
Attack Vector
Exploitation requires only network access to the target WordPress site. An attacker sends a crafted HTTP request to the refund request endpoint referencing a guest order identifier. No authentication, user interaction, or elevated privileges are required. Consult the WPScan Vulnerability Report for endpoint specifics and reproduction details.
Detection Methods for CVE-2026-77701
Indicators of Compromise
- Unexpected refund request records in the WCFM Marketplace database tied to guest orders.
- Vendor notifications about refund requests that customers did not initiate.
- Spikes in POST requests to WCFM refund-related endpoints from a small set of source IP addresses.
Detection Strategies
- Review WCFM refund logs and correlate refund creation timestamps with customer-initiated activity or session data.
- Inspect webserver access logs for repeated requests to WCFM refund endpoints, especially with sequential or enumerated order IDs.
- Alert on refund requests created without an authenticated WordPress session cookie present in the originating request.
Monitoring Recommendations
- Enable verbose logging on the WooCommerce and WCFM order and refund subsystems.
- Monitor for anomalous increases in refund request volume across vendors.
- Forward WordPress and web server logs to a centralized analytics platform for correlation and retention.
How to Mitigate CVE-2026-77701
Immediate Actions Required
- Upgrade the WCFM Marketplace plugin to version 3.8.2 or later on all affected WordPress sites.
- Audit refund request records created before the upgrade to identify unauthorized entries.
- Notify vendors and affected guest customers if unauthorized refund requests are found.
Patch Information
The vendor addressed CVE-2026-77701 in WCFM Marketplace version 3.8.2. The fix introduces ownership verification on refund requests so that only the original purchaser, or an authenticated session bound to the guest order, can submit a refund. Refer to the WPScan Vulnerability Report for confirmation of the fixed version.
Workarounds
- Disable guest checkout on WooCommerce until the plugin is patched, forcing account-based purchases with authenticated refund requests.
- Apply web application firewall rules to block unauthenticated access to WCFM refund request endpoints.
- Restrict access to WCFM refund URLs by IP allowlist where operationally feasible until the upgrade is completed.
# Configuration example: temporarily block unauthenticated access to WCFM refund endpoints via WAF/nginx
location ~* /wcfm/.*refund {
if ($http_cookie !~ "wordpress_logged_in") {
return 403;
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
