Wclovers develops a suite of WooCommerce marketplace and vendor-management plugins that extend WordPress e-commerce functionality, including multivendor platforms, membership systems, and frontend management tools. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs across its product line through authorization and authentication weaknesses such as missing authorization checks, CSRF, SQL injection, and cross-site scripting that are characteristic of web-application plugins operating in shared WordPress environments. Defenders should prioritize updates to these plugins given their position in the payment and vendor-management workflow of hosted marketplaces; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wclovers over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24849CRITICAL The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multipl | Dec 21, 2021 | 9.8 | 45 | NO | YES |
CVE-2022-4940MEDIUM The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on | Apr 5, 2023 | 6.5 | 31 | NO | YES |
CVE-2023-2276CRITICAL The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, | May 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-4939CRITICAL THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm | Apr 5, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-42753HIGH Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect | May 27, 2026 | 7.3 | 27 | NO | NO |
CVE-2022-4938HIGH The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing nonce checks on various AJAX actio | Apr 5, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-4937HIGH The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability check | Apr 5, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-24835HIGH The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCom | Nov 8, 2021 | 8.8 | 27 | NO | NO |
CVE-2025-63029HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows SQL Injection.Thi | Apr 15, 2026 | 7.6 | 26 | NO | NO |
CVE-2022-4936HIGH The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce checks on various AJAX actions. | Apr 5, 2023 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wclovers.
Media articles that mention a CVE ID that affects a product developed by Wclovers — matched by CVE ID, not by vendor name.