← Terug naar overzicht

A critical unauthenticated SQL injection vulnerability has been identified in the WCFM Marketplace WordPress plugin affecting versions 3.8.1 and below. The vulnerability allows unauthenticated attackers to inject malicious SQL queries, potentially enabling unauthorized access to the database, data exfiltration, or full database compromise. No authentication is required to exploit this flaw, significantly raising its risk level. The vulnerability is tracked as CVE-2026-81286 and has been documented by both the National Vulnerability Database (NVD) and Patchstack. Users of the WCFM Marketplace plugin are strongly advised to update to a patched version immediately. The plugin is widely used in WordPress-based multi-vendor marketplace setups, increasing the potential attack surface. SQL injection vulnerabilities of this nature can lead to complete site takeover if exploited in combination with other weaknesses.

Affected products

  • WCFM Marketplace WordPress Plugin <= 3.8.1

Related CVE's

  • CVE-2026-81286

Categories

  • Database & Storage
  • Enterprise Applications
  • Web Technologies