CVE-2026-12994

WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to inject arbitrary reply content into any store inquiry, overwrite the main inquiry record in wp_wcfm_enquiries, and trigger unsolicited notification emails to customers and vendors. Unlike sibling controller branches (wcfm-enquiry and wcfm-enquiry-manage), the wcfm-my-account-enquiry-manage branch performs no is_user_logged_in() or current_user_can() check, and the nonce that serves as the sole barrier is embedded into every public page load without any login gate.


We have discovered 1,941 live websites that are affected by CVE-2026-12994.

Run a Free Instant Scan




Affected Software

Product  Wc Frontend Manager
Category Wordpress Plugins
Vulnerable Domains1,941 live websites (98% of Wc Frontend Manager install base)
Vulnerable Versions
  • from 0 through 6.7.27
Vulnerable Versions Count54 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jul 11, 2026
  • Updated - Jul 13, 2026

Credits

  • Niv Kochan (finder)

Website Distribution by Country

Number of websites using CVE-2026-12994
United States611 websites



Germany126 websites
GB123 websites
France112 websites
Brazil79 websites
India78 websites
Italy76 websites
Cyprus75 websites
Spain62 websites
South Africa49 websites

Website Distribution by TLD

Number of websites using CVE-2026-12994
.com955 websites
.com.br79 websites
.it59 websites
.co.uk46 websites
.de45 websites
.org43 websites
.fr38 websites
.net38 websites
.com.au29 websites
.es26 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12994

Top websites that are affected by CVE-2026-12994. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States***,***
******.*********.com United States***,***
***************.de Germany***,***
********.com United States***,***
************.com United States***,***
*****.com United States***,***
*******.***************.de Germany***,***
********.******.net Bulgaria***,***
***.***.au Australia***,***
***********.com United States***,***
See full domain list

FAQ

CVE-2026-12994 is Missing Authorization in Wc Frontend Manager
A total of 1,941 websites have been identified as vulnerable to CVE-2026-12994, based on global website indexing conducted by WebTechSurvey.
The Wc Frontend Manager is affected by the CVE-2026-12994 vulnerability.
Wc Frontend Manager versions up to and including 6.7.27 are vulnerable to CVE-2026-12994.

References