CVE-2026-83562 Overview
CVE-2026-83562 is a Cross-Site Scripting (XSS) vulnerability affecting the WCFM Marketplace plugin for WordPress in versions up to and including 3.8.2. The flaw allows authenticated users with contributor-level privileges to inject malicious script content that executes in the browsers of other users who view the affected pages. The vulnerability is categorized under CWE-79, Improper Neutralization of Input During Web Page Generation.
Critical Impact
Authenticated contributors can inject JavaScript that executes in victim browsers, enabling session theft, credential harvesting, and administrative account compromise across multi-vendor WooCommerce storefronts.
Affected Products
- WordPress plugin: WCFM Marketplace (wc-multivendor-marketplace)
- Versions <= 3.8.2
- WooCommerce-based multi-vendor storefronts using the affected plugin
Discovery Timeline
- 2026-09-02 - CVE-2026-83562 published to the National Vulnerability Database
- 2026-09-02 - Last updated in NVD database
Technical Details for CVE-2026-83562
Vulnerability Analysis
The vulnerability resides in the WCFM Marketplace plugin, which extends WooCommerce with multi-vendor marketplace functionality. A user holding contributor-level access can submit crafted input that the plugin fails to properly neutralize before rendering it in generated HTML output. When another user, such as a store administrator or shopper, loads the page containing this input, the browser executes the attacker-controlled script within the site's origin.
The scope change indicated by the CVSS vector (S:C) means that the impact of the injected payload can extend beyond the vulnerable component. Successful exploitation requires user interaction, such as an administrator visiting a vendor product page or dashboard view. See the Patchstack Vulnerability Report for advisory details.
Root Cause
The root cause is improper output encoding and input sanitization within plugin code paths accessible to contributor-role users. Fields that accept vendor-supplied content are rendered without adequate escaping using WordPress functions such as esc_html(), esc_attr(), or wp_kses(). This allows HTML and JavaScript payloads to pass through into the DOM.
Attack Vector
Exploitation is performed over the network by an authenticated attacker with contributor privileges. The attacker submits a payload containing script content through a vulnerable input field exposed by the plugin. When a privileged user opens the resulting page, the payload executes in that user's browser session and can perform actions on their behalf.
No verified public exploit code is available for CVE-2026-83562. Refer to the vendor advisory linked above for technical specifics of the affected code paths.
Detection Methods for CVE-2026-83562
Indicators of Compromise
- Unexpected <script> tags, event handlers (onerror, onclick, onload), or javascript: URIs stored in WCFM vendor profile, product, or store fields.
- WordPress user sessions originating from unfamiliar IP addresses shortly after an administrator viewed a vendor page.
- Newly created administrator accounts or modified user roles without a corresponding audit trail entry.
Detection Strategies
- Audit the WordPress database (wp_posts, wp_postmeta, wp_usermeta) for stored HTML or script payloads within WCFM-managed fields.
- Inspect web server access logs for POST requests to WCFM endpoints originating from contributor-role accounts.
- Deploy Content Security Policy (CSP) reporting to surface inline script execution attempts on marketplace pages.
Monitoring Recommendations
- Monitor creation and modification events for contributor and vendor accounts, especially those preceding administrator sessions.
- Alert on outbound requests from administrator browsers to unknown domains that could indicate exfiltration by injected scripts.
- Track plugin version inventory across WordPress deployments to identify hosts still running WCFM Marketplace <= 3.8.2.
How to Mitigate CVE-2026-83562
Immediate Actions Required
- Update the WCFM Marketplace plugin to a version later than 3.8.2 as soon as the vendor releases a patched build.
- Review all contributor and vendor accounts, disable those that are inactive or unrecognized, and rotate credentials for privileged accounts.
- Audit stored vendor content for embedded HTML or JavaScript and remove any suspicious entries.
Patch Information
A fixed version addressing CVE-2026-83562 should be applied following guidance in the Patchstack Vulnerability Report. Confirm the installed version through the WordPress plugin management interface after upgrading.
Workarounds
- Restrict contributor role assignments and require review before granting vendor access on marketplace deployments.
- Deploy a web application firewall rule that inspects and blocks payloads containing script tags or JavaScript event handlers submitted to WCFM plugin endpoints.
- Enforce a strict Content Security Policy that disallows inline scripts and untrusted script sources on WordPress administrative and vendor-facing pages.
# Verify installed WCFM Marketplace plugin version via WP-CLI
wp plugin get wc-multivendor-marketplace --field=version
# Update the plugin once a patched release is available
wp plugin update wc-multivendor-marketplace
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
