Vulnerabilities > Wclovers > Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible > 6.6.5

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-8290 Authorization Bypass Through User-Controlled Key vulnerability in Wclovers Frontend Manager for Woocommerce Along With Bookings Subscription Listings Compatible
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_Manage_Controller::processing function due to missing validation on the ID user controlled key.
network
low complexity
wclovers CWE-639
8.8