<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wcfm:marketplace_multivendor_marketplace_for_woocommerce:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awcfmmarketplace_multivendor_marketplace_for_woocommerce/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 10:05:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awcfmmarketplace_multivendor_marketplace_for_woocommerce/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in WCFM Marketplace Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-wcfm-sql-injection/</link><pubDate>Fri, 18 Sep 2026 10:05:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-wcfm-sql-injection/</guid><description>The WCFM Marketplace plugin for WordPress is vulnerable to unauthenticated SQL injection via the wcfmmp_user_location_lng parameter, allowing attackers to extract sensitive database information.</description><content:encoded><![CDATA[<p>The WCFM Marketplace - Multivendor Marketplace for WooCommerce plugin for WordPress is affected by a SQL injection vulnerability (CVE-2026-18442) in versions up to and including 3.8.2. The flaw exists due to improper input sanitization and insufficient preparation of SQL queries involving the 'wcfmmp_user_location_lng' parameter. Because the plugin does not correctly escape user-supplied data before passing it to the database, unauthenticated attackers can craft malicious inputs to manipulate backend queries. Successful exploitation allows for the execution of arbitrary SQL commands, which may lead to unauthorized access to sensitive site information, including user credentials, configuration details, and customer transaction records. Defenders should prioritize updating to the latest secure version of the plugin and monitoring web access logs for anomalous character sequences in parameters associated with location data.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a high risk to WordPress environments running the WCFM Marketplace plugin. If exploited, an unauthenticated attacker can perform unauthorized database queries, potentially leading to the full compromise of the database contents. This impacts the confidentiality and integrity of all store data, including personal identifiable information (PII) of vendors and customers, and could facilitate further stages of an attack chain such as account takeover or lateral movement within the WordPress environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the WCFM Marketplace - Multivendor Marketplace for WooCommerce plugin to the latest version that addresses CVE-2026-18442.</li>
<li>Deploy the provided Sigma rule to web server access logs to detect potential exploitation attempts.</li>
<li>Review web server access logs for HTTP requests containing SQL injection patterns such as comments (--), union statements, or common escape characters within the 'wcfmmp_user_location_lng' parameter.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>