CVE-2026-14196

WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR

The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, allowing any vendor to modify or permanently delete reviews belonging to other vendors' stores.


We have discovered 648 live websites that are affected by CVE-2026-14196.

Run a Free Instant Scan




Affected Software

Product  Wc Multivendor Marketplace
Category Wordpress Plugins
Vulnerable Domains648 live websites (100% of Wc Multivendor Marketplace install base)
Vulnerable Versions
  • from 0 through 3.8.1
Vulnerable Versions Count35 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Aug 19, 2026
  • Updated - Aug 19, 2026

Credits

  • Mustafa Ahmed (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14196
United States213 websites



GB44 websites
Germany42 websites
India37 websites
Cyprus30 websites
France26 websites
Italy24 websites
Spain19 websites
Canada14 websites
Brazil13 websites

Website Distribution by TLD

Number of websites using CVE-2026-14196
.com338 websites
.net19 websites
.it18 websites
.co.uk16 websites
.de15 websites
.org13 websites
.com.br12 websites
.ru11 websites
.com.au10 websites
.fr8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14196

Top websites that are affected by CVE-2026-14196. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.**.uk GB***,***
*********************.com France***,***
*********.com United States***,***
***********.com Cyprus*,***,***
*********.no Norway*,***,***
**********.ch Switzerland*,***,***
******.us United States*,***,***
****.********.**.il Israel*,***,***
*******.it Italy*,***,***
***********.com France*,***,***
See full domain list

FAQ

CVE-2026-14196 is Authorization Bypass Through User-Controlled Key in Wc Multivendor Marketplace
A total of 648 websites have been identified as vulnerable to CVE-2026-14196, based on global website indexing conducted by WebTechSurvey.
The Wc Multivendor Marketplace is affected by the CVE-2026-14196 vulnerability.
Wc Multivendor Marketplace versions up to 3.8.1 are vulnerable to CVE-2026-14196.
CVE-2026-14196 is resolved in version 3.8.1 of Wc Multivendor Marketplace.