Sceawere

Vulnerability Detail

CVE-2026-32480UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WCFM Membership Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
WC Lovers
Product
WCFM Membership
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-04T09:17:10.677Z",
  "pubdate": "2026-09-04T09:17:10.677Z",
  "executiveSummary": "WCFM Membership, in versions up to and including 2.11.11, contains a critical security flaw categorized as a Missing Authorization vulnerability.\nThis vulnerability stems from improperly configured access control security levels, which allows unauthorized users to perform actions restricted to higher-privileged accounts.\nThe flaw affects the overall security posture of the WCFM Membership plugin by bypassing existing authorization mechanisms.\nAn unauthenticated or low-privileged attacker can exploit this weakness to interact with restricted functionality, potentially leading to unauthorized data manipulation, access to sensitive plugin configurations, or the execution of administrative actions.\nSuccessful exploitation requires the attacker to identify and interact with the vulnerable endpoints or functions that lack adequate access control checks.\nThe risk implication is significant as it undermines the integrity and confidentiality of the plugin settings and user data managed by WCFM Membership.",
  "technicalDetails": "The root cause of the vulnerability lies in the insufficient enforcement of authorization checks within the WCFM Membership codebase. Specifically, the plugin fails to properly validate the user's role or capabilities before executing requests to specific administrative functions.\nInsecurely configured access control lists or missing permission checks within the plugin's controller or handler functions allow requests to proceed without verifying that the requester possesses the necessary authorization level (e.g., administrator or shop manager).\nThe exploitation method involves an attacker crafting HTTP requests targeting the vulnerable endpoints that lack server-side authorization validation. By manipulating the request parameters or simply accessing these restricted URLs directly, an attacker can bypass the intended access restrictions imposed by the plugin's architectural design.\nThe attack flow typically follows this trajectory: 1. The attacker identifies internal administrative or restricted endpoints provided by WCFM Membership. 2. The attacker triggers these endpoints via GET or POST requests without supplying the required administrative session tokens or credentials. 3. Due to the lack of access control middleware or verification logic, the application processes the request, assuming authorized origin.\nThe vulnerable component is the underlying authorization logic governing access to restricted WCFM Membership features. This failure impacts versions from n/a through 2.11.11.\nThis vulnerability does not strictly require high-level authentication if the authorization checks are missing entirely for specific entry points. However, it is fundamentally a privilege escalation or unauthorized action vulnerability where a lower-privileged user can perform operations reserved for higher-privileged accounts.\nNetwork exposure is defined by the availability of the WCFM Membership plugin on the WordPress installation. Because the flaw exists within the plugin's internal handling of requests, any remote user capable of interacting with the WordPress REST API or other registered hooks can potentially reach the vulnerable functions.\nPost-exploitation impact includes the modification of membership settings, potential data leaks related to member information, and unauthorized administrative actions within the WCFM ecosystem. The impact is dictated by the specific functions protected by the missing authorization checks."
}
CVE-2026-32480: WCFM Membership Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere