CPE
The WCFM Marketplace plugin for WordPress is vulnerable to unauthenticated SQL injection via the wcfmmp_user_location_lng parameter, allowing attackers to extract sensitive database information.