CVE-2026-77701 UNKNOWN

CVE-2026-77701

Published: 2026-08-28

Description

The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…