
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Security & Risk Analysis
wordpress.org/plugins/wc-multivendor-membershipA simple woocommerce memberships plugin for offering free and premium subscription for your multi-vendor marketplace - WCFM Marketplace, WC Vendors &a …
Is WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Safe to Use in 2026?
Mostly Safe
Score 83/100WCFM Membership – WooCommerce Memberships for Multivendor Marketplace is generally safe to use. 5 past CVEs were resolved. Keep it updated.
The "wc-multivendor-membership" plugin v2.11.9 exhibits a mixed security posture. While the static analysis reveals strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and a high percentage of outputs properly escaped, there are areas of concern. Notably, the presence of two unsanitized paths in the taint analysis, although not leading to critical or high severity vulnerabilities in this version, warrants careful attention as it indicates potential entry points for malicious input.
The plugin's vulnerability history is a significant red flag. With a total of 5 known CVEs, including 2 critical and 1 high severity, and past common vulnerability types like Authorization Bypass and Missing Authorization, it suggests a recurring pattern of security weaknesses. The fact that all previously disclosed vulnerabilities are currently patched is a positive sign, but the historical prevalence of severe issues implies a need for ongoing vigilance and robust testing.
In conclusion, while the current version's static analysis shows improved security controls, the plugin's past security record necessitates caution. The combination of historical severe vulnerabilities and the identified unsanitized paths in the taint analysis means that while the immediate risk in this specific version might be lower due to patched CVEs, the potential for future vulnerabilities should not be underestimated. Continuous monitoring and prompt application of updates are highly recommended.
Key Concerns
- History of 2 critical CVEs
- History of 1 high CVE
- History of 2 medium CVEs
- Flows with unsanitized paths (2)
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecure Direct Object Reference to Update Membership Payment
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.10.7 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Password Change
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
WCFM Membership <= 2.9.10 - Cross-Site Request Forgery
WCFM Membership <= 2.10.0 - Missing Authorization
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Attack Surface
AJAX Handlers 18
Shortcodes 3
WordPress Hooks 62
Maintenance & Trust
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Maintenance & Trust
Maintenance Signals
Community Trust
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Alternatives
PG Sync for Klaviyo and Woo Memberships and Subscriptions
pg-sync-for-klaviyo-and-woo-memberships-and-subscriptions
This is a very lightweight plugin that synchs WooCommerce Memberships (and optionally Subscriptions) to Klaviyo.
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
user-registration
Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
dokan-lite
Transform your WooCommerce site into a multivendor marketplace with Dokan – an AI powered & advanced WooCommerce marketplace solution
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
wc-frontend-manager
Vendor frontend store/shop manager for WC Marketplace, WC Vendors, WC Product Vendors & Dokan with Bookings, Listings & Subscriptions compatib …
WCFM Marketplace – Multivendor Marketplace for WooCommerce
wc-multivendor-marketplace
The most featured and powerful multi vendor plugin for WordPress, setup fantastic woocommerce marketplace store in minutes.
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Developer Profile
7 plugins · 52K total installs
How We Detect WCFM Membership – WooCommerce Memberships for Multivendor Marketplace
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-multivendor-membership/assets/js/wcfmvm-scripts.js/wp-content/plugins/wc-multivendor-membership/assets/css/wcfmvm-styles.css/wp-content/plugins/wc-multivendor-membership/assets/css/wcfmvm-responsive.css/wp-content/plugins/wc-multivendor-membership/assets/js/frontend/wcfmvm-frontend.js/wp-content/plugins/wc-multivendor-membership/assets/js/wcfmvm-scripts.js/wp-content/plugins/wc-multivendor-membership/assets/js/frontend/wcfmvm-frontend.jswc-multivendor-membership/assets/js/wcfmvm-scripts.js?ver=wc-multivendor-membership/assets/css/wcfmvm-styles.css?ver=wc-multivendor-membership/assets/css/wcfmvm-responsive.css?ver=wc-multivendor-membership/assets/js/frontend/wcfmvm-frontend.js?ver=HTML / DOM Fingerprints
wcfmvm_membership_detailswcfmvm_membership_planwcfmvm_membership_formwcfmvm_membership_tablewcfmvm_membership_wrapwcfmvm_vendor_membership<!-- WCFM Membership Page Template --><!-- WCFM Membership End Points --><!-- WCFM Membership Page --><!-- WCFM Membership Endpoint Edit -->+12 moredata-wcfmvm_plan_iddata-wcfmvm_vendor_idWCFMvm_frontend_params/wp-json/wcfmvm/v1/membership/settings/wp-json/wcfmvm/v1/membership/plans/wp-json/wcfmvm/v1/membership/vendors/wp-json/wcfmvm/v1/membership/purchase/wp-json/wcfmvm/v1/membership/renew[wcfm_vendor_membership]