Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wclovers

First CVE: Nov 8, 2021Active for: 5 yearsTotal CVEs: 18
47.4
VTI Score
High

Wclovers develops a suite of WooCommerce marketplace and vendor-management plugins that extend WordPress e-commerce functionality, including multivendor platforms, membership systems, and frontend management tools. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs across its product line through authorization and authentication weaknesses such as missing authorization checks, CSRF, SQL injection, and cross-site scripting that are characteristic of web-application plugins operating in shared WordPress environments. Defenders should prioritize updates to these plugins given their position in the payment and vendor-management workflow of hosted marketplaces; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wclovers over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2021
4 years ago
Most Recent CVE
May 27, 2026
59 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24849CRITICAL
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multipl
Dec 21, 20219.845NOYES
CVE-2022-4940MEDIUM
The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on
Apr 5, 20236.531NOYES
CVE-2023-2276CRITICAL
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including,
May 20, 20239.830NONO
CVE-2022-4939CRITICAL
THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm
Apr 5, 20239.829NONO
CVE-2026-42753HIGH
Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect
May 27, 20267.327NONO
CVE-2022-4938HIGH
The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing nonce checks on various AJAX actio
Apr 5, 20238.827NONO
CVE-2022-4937HIGH
The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability check
Apr 5, 20238.827NONO
CVE-2021-24835HIGH
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCom
Nov 8, 20218.827NONO
CVE-2025-63029HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows SQL Injection.Thi
Apr 15, 20267.626NONO
CVE-2022-4936HIGH
The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce checks on various AJAX actions.
Apr 5, 20238.826NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
33%
50%
17%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (72.2%)
Unknown0 (0.0%)
Required5 (27.8%)
Privileges Required
Low7 (38.9%)
High1 (5.6%)
None10 (55.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wclovers.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wclovers — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wclovers's Products

View all 3 CNAs →

Top CWEs