
WCFM – Multivendor Marketplace REST API for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wcfm-marketplace-rest-apiREST API for the most featured and powerful multi vendor plugin for your WooCommerce Multi-vendor Marketplace.
Is WCFM – Multivendor Marketplace REST API for WooCommerce Safe to Use in 2026?
Generally Safe
Score 91/100WCFM – Multivendor Marketplace REST API for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of wcfm-marketplace-rest-api v1.6.3 reveals a generally strong security posture regarding its immediate attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that present an immediate entry point for exploitation. Furthermore, the code demonstrates good practices in its use of prepared statements for all SQL queries and proper output escaping for all identified outputs, with no file operations or external HTTP requests to consider. The presence of capability checks, even without nonce checks being explicitly identified on specific entry points (which are absent), suggests an awareness of authorization mechanisms.
However, the vulnerability history presents a significant concern. The plugin has a history of two known medium severity CVEs, specifically related to SQL Injection and Missing Authorization. While currently none are listed as unpatched, the presence of these past vulnerabilities, particularly in common WordPress plugin security flaws, indicates potential underlying weaknesses that might not be fully mitigated in this version. The fact that these past issues were 'Improper Neutralization of Special Elements used in an SQL Command' and 'Missing Authorization' is concerning given the limited attack surface identified in the current code analysis, suggesting that previous vulnerabilities might have existed on attack vectors that are no longer present or were patched imperfectly.
In conclusion, while v1.6.3 of wcfm-marketplace-rest-api appears to have a clean static analysis report concerning its immediate attack surface and coding practices like prepared statements and output escaping, the historical vulnerability data cannot be ignored. The past presence of medium-severity SQL Injection and Missing Authorization vulnerabilities suggests a need for continued vigilance and thorough auditing to ensure no residual or newly introduced risks exist. The absence of critical or high severity issues in the current analysis is positive, but the historical pattern warrants a cautious approach.
Key Concerns
- Two known medium CVEs
- Past SQL Injection vulnerability
- Past Missing Authorization vulnerability
WCFM – Multivendor Marketplace REST API for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WooCommerce Multivendor Marketplace – REST API <= 1.6.2 - Authenticated (Subscriber+) SQL Injection
WooCommerce Multivendor Marketplace – REST API <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order/Order Note Disclosure, Order Note Addition via REST API
WCFM – Multivendor Marketplace REST API for WooCommerce Release Timeline
WCFM – Multivendor Marketplace REST API for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
WCFM – Multivendor Marketplace REST API for WooCommerce Attack Surface
WordPress Hooks 14
Maintenance & Trust
WCFM – Multivendor Marketplace REST API for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WCFM – Multivendor Marketplace REST API for WooCommerce Alternatives
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
Disable REST API
disable-json-api
Disable the use of the REST API on your website to site users. Now with User Role support!
Make Connector
integromat-connector
Make Connector. Make lets you design, build, and automate by connecting with WordPress in just a few clicks.
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
Disable WP REST API
disable-wp-rest-api
Disables the WP REST API for visitors not logged into WordPress.
WCFM – Multivendor Marketplace REST API for WooCommerce Developer Profile
7 plugins · 42K total installs
How We Detect WCFM – Multivendor Marketplace REST API for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wcfm-marketplace-rest-api/includes/api//wp-content/plugins/wcfm-marketplace-rest-api/core/HTML / DOM Fingerprints
wcfm_product_policy_dataproduct_restirction_messagewcfm_product_policy_data[visible]wcfm_product_policy_data[shipping_policy]wcfm_product_policy_data[shipping_policy_heading]wcfm_product_policy_data[refund_policy]+6 moreWCFMapi/wp-json/wcfm-marketplace-rest-api//wp-json/wcfm-marketplace-rest-api/product//wp-json/wcfm-marketplace-rest-api/product-attribute//wp-json/wcfm-marketplace-rest-api/product-categories//wp-json/wcfm-marketplace-rest-api/order//wp-json/wcfm-marketplace-rest-api/settings//wp-json/wcfm-marketplace-rest-api/capabilities//wp-json/wcfm-marketplace-rest-api/notification//wp-json/wcfm-marketplace-rest-api/booking//wp-json/wcfm-marketplace-rest-api/site_details//wp-json/wcfm-marketplace-rest-api/sales_stats//wp-json/wcfm-marketplace-rest-api/enquiry//wp-json/wcfm-marketplace-rest-api/review//wp-json/wcfm-marketplace-rest-api/store_vendors//wp-json/wcfm-marketplace-rest-api/deliveries//wp-json/wcfm-marketplace-rest-api/support//wp-json/wcfm-marketplace-rest-api/customer_app_settings//wp-json/wcfm-marketplace-rest-api/user_profile//wp-json/wcfm-marketplace-rest-api/wc_cart//wp-json/wcfm-marketplace-rest-api/wc_checkout//wp-json/wcfm-marketplace-rest-api/wc_product_variation/