← Back to overview

A critical unauthenticated SQL injection vulnerability has been identified in the WCFM Marketplace WordPress plugin affecting versions 3.8.1 and below. The vulnerability allows unauthenticated attackers to inject malicious SQL queries, potentially leading to unauthorized database access, data exfiltration, or full site compromise. No authentication is required to exploit this flaw, making it particularly dangerous for any site running the affected plugin versions. The issue is tracked as CVE-2026-81286 and has been documented by both the National Vulnerability Database (NVD) and Patchstack. Site administrators using WCFM Marketplace are strongly advised to update to a patched version immediately to mitigate the risk of exploitation.

Affected products

  • WCFM Marketplace WordPress Plugin <= 3.8.1

Related CVE's

  • CVE-2026-81286

Categories

  • Database & Storage
  • Enterprise Applications
  • Web Technologies