CVE-2026-10041

WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to archive arbitrary vendors' products, toggle the featured status on arbitrary listings, mark arbitrary WooCommerce orders as completed, and permanently delete arbitrary enquiries and bulk messages belonging to other vendors.


We have discovered 1,941 live websites that are affected by CVE-2026-10041.

Run a Free Instant Scan




Affected Software

Product  Wc Frontend Manager
Category Wordpress Plugins
Vulnerable Domains1,941 live websites (98% of Wc Frontend Manager install base)
Vulnerable Versions
  • from 0 through 6.7.27
Vulnerable Versions Count54 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Jul 11, 2026
  • Updated - Jul 13, 2026

Credits

  • mrholmes (finder)
  • papadope (finder)

Website Distribution by Country

Number of websites using CVE-2026-10041
United States611 websites



Germany126 websites
GB123 websites
France112 websites
Brazil79 websites
India78 websites
Italy76 websites
Cyprus75 websites
Spain62 websites
South Africa49 websites

Website Distribution by TLD

Number of websites using CVE-2026-10041
.com955 websites
.com.br79 websites
.it59 websites
.co.uk46 websites
.de45 websites
.org43 websites
.fr38 websites
.net38 websites
.com.au29 websites
.es26 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-10041

Top websites that are affected by CVE-2026-10041. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States***,***
******.*********.com United States***,***
***************.de Germany***,***
********.com United States***,***
************.com United States***,***
*****.com United States***,***
*******.***************.de Germany***,***
********.******.net Bulgaria***,***
***.***.au Australia***,***
***********.com United States***,***
See full domain list

FAQ

CVE-2026-10041 is Authorization Bypass Through User-Controlled Key in Wc Frontend Manager
A total of 1,941 websites have been identified as vulnerable to CVE-2026-10041, based on global website indexing conducted by WebTechSurvey.
The Wc Frontend Manager is affected by the CVE-2026-10041 vulnerability.
Wc Frontend Manager versions up to and including 6.7.27 are vulnerable to CVE-2026-10041.

References