
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15147 is an Insecure Direct Object Reference (IDOR) vulnerability in the WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress. It affects all versions up to and including 2.11.8, allowing authenticated attackers with Subscriber-level access or above to modify other users' membership payment records. The vulnerability was published on February 10, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE).
The root cause is an Authorization Bypass Through User-Controlled Key (CWE-639) in the WCFMvm_Memberships_Payment_Controller::processing function. The function fails to validate that the user-controlled key (e.g., a payment or membership record ID) belongs to the requesting user, enabling any authenticated subscriber to reference and modify payment records belonging to other users. No special configuration or elevated privileges beyond a basic subscriber account are required to exploit this flaw (Red Hat CVE).
Successful exploitation allows an authenticated attacker to tamper with other users' membership payment data, resulting in an integrity impact on the affected WordPress multivendor marketplace. While there is no confidentiality or availability impact, attackers could manipulate payment statuses, potentially granting unauthorized membership access or disrupting legitimate payment records for other users (Red Hat CVE).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-15147. The EPSS score is extremely low at approximately 0.008%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (Red Hat CVE).
WCFMvm_Memberships_Payment_Controller::processing, substituting the user-controlled key (payment/membership record ID) with a value belonging to another user.Users should update the WCFM Membership plugin to a version beyond 2.11.8 that includes a fix for this vulnerability. As of the disclosure date, no patched version was confirmed publicly available; site administrators should monitor the plugin's official WordPress repository for an updated release. In the interim, consider restricting subscriber-level account registration or implementing a web application firewall rule to monitor and block suspicious requests to the WCFM payment processing endpoint (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."