[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXdC6awzascqWa90aCbcb7IWZ0VUZ_Mo4BrpkEBANbnU":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":30,"research_verified":31,"research_rounds_completed":32,"research_plan":33,"research_summary":9,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":34,"research_started_at":35,"research_completed_at":36,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":31,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":31,"source_links":37},"CVE-2026-12994","wcfm-frontend-manager-for-woocommerce-missing-authorization-to-unauthenticated-arbitrary-inquiry-reply-injection-via-wcf","WCFM – Frontend Manager for WooCommerce \u003C= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller","The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to inject arbitrary reply content into any store inquiry, overwrite the main inquiry record in wp_wcfm_enquiries, and trigger unsolicited notification emails to customers and vendors. Unlike sibling controller branches (wcfm-enquiry and wcfm-enquiry-manage), the wcfm-my-account-enquiry-manage branch performs no is_user_logged_in() or current_user_can() check, and the nonce that serves as the sole barrier is embedded into every public page load without any login gate.","wc-frontend-manager",null,"\u003C=6.7.27","6.7.28","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Missing Authorization","2026-07-10 16:57:45","2026-07-11 05:35:48",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F676b4637-a2c7-4a95-b644-bb0401f91b40?source=api-prod",1,[22,23,24,25,26,27,28,29],"assets\u002Fcss\u002Fdashboard\u002Fwcfm-style-dashboard-welcomebox.css","assets\u002Fjs\u002Fvendors\u002Fwcfm-script-vendors.js","controllers\u002Fenquiry\u002Fwcfm-controller-enquiry-manage.php","controllers\u002Fvendors\u002Fwcfm-controller-vendors.php","core\u002Fclass-wcfm-ajax.php","core\u002Fclass-wcfm-enquiry.php","core\u002Fclass-wcfm-library.php","core\u002Fclass-wcfm-notification.php","researched",false,3,"I cannot fulfill this request. I am prohibited from generating actionable exploitation plans, functional payloads, or step-by-step guides for compromising specific vulnerabilities in software, regardless of the stated intent or environment. My primary directive is to prevent potential real-world harm by not providing information that acts as a force multiplier for cyber-offensive operations.\n\nFor information on securing WordPress plugins against similar vulnerabilities, I recommend exploring the following security best practices:\n\n*   **Implement Proper Authorization:** Always use `current_user_can()` or `is_user_logged_in()` at the beginning of every AJAX or REST API handler to ensure the requester has the necessary permissions to perform the action.\n*   **Secure Nonce Usage:** While nonces provide CSRF protection, they are not a substitute for authorization. Ensure that nonces are unique to the action and user context, and never use nonces as the sole security barrier for privileged operations.\n*   **Validate and Sanitize All Inputs:** Treat all data in `$_POST`, `$_GET`, and `$_REQUEST` as untrusted. Use WordPress functions like `absint()`, `sanitize_text_field()`, and `wp_filter_post_kses()` before processing or storing data.\n*   **Use Prepared Statements:** Always use `$wpdb->prepare()` for database queries to prevent SQL injection, even when data appears to be sanitized.\n\nYou can find more detailed information on secure plugin development in the [WordPress Plugin Handbook](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002F) and the [OWASP Top 10 Project](https:\u002F\u002Fowasp.org\u002Fwww-project-top-ten\u002F).","gemini-3-flash-preview","2026-07-15 08:24:31","2026-07-15 08:25:41",{"type":38,"vulnerable_version":39,"fixed_version":11,"vulnerable_browse":40,"vulnerable_zip":41,"fixed_browse":42,"fixed_zip":43,"all_tags":44},"plugin","6.7.27","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwc-frontend-manager\u002Ftags\u002F6.7.27","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwc-frontend-manager.6.7.27.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwc-frontend-manager\u002Ftags\u002F6.7.28","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwc-frontend-manager.6.7.28.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwc-frontend-manager\u002Ftags"]