← WordPress Vulnerabilities
WordPress security by component

WCFM – Frontend Manager for WooCommerce

WCFM – Frontend Manager for WooCommerce is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Jul 11, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: wc-frontend-manager

CVE-2026-12994: WCFM – Frontend Manager for WooCommerce: A security weakness

WCFM – Frontend Manager for WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.7.27.

PublishedJul 11, 2026
Known safe version> 6.7.27
Safe version
Jul 11, 2026 CVE-2026-12994
WCFM – Frontend Manager for WooCommerce: A security weakness
WCFM – Frontend Manager for WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.7.27.
> 6.7.27
CVE5.3
NVDPending
Jul 11, 2026 CVE-2026-10041
WCFM – Frontend Manager for WooCommerce: A security weakness
WCFM – Frontend Manager for WooCommerce is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.7.27.
> 6.7.27
CVE4.3
NVDPending
May 02, 2026 CVE-2026-2554
WCFM – Frontend Manager for WooCommerce: A security weakness
WCFM – Frontend Manager for WooCommerce is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.7.25.
> 6.7.25
CVE8.1
NVDPending
Apr 04, 2026 CVE-2026-4896
WCFM – Frontend Manager for WooCommerce: A security weakness
WCFM – Frontend Manager for WooCommerce is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.7.25.
> 6.7.25
CVE8.1
NVDPending
Feb 10, 2026 CVE-2026-0845
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible: Privilege escalation or authentication bypass
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.2
NVDPending
Dec 16, 2025 CVE-2025-54004
WCFM – Frontend Manager for WooCommerce: A security weakness
WCFM – Frontend Manager for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE2.7
NVDPending
Jul 09, 2025 CVE-2025-3780
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible: A security weakness
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Sep 25, 2024 CVE-2024-8290
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible: A security weakness
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVDPending
Mar 27, 2024 CVE-2024-29929
WCFM – Frontend Manager for WooCommerce: Cross-site scripting
WCFM – Frontend Manager for WooCommerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending