CVE-2026-1722: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1722 is an Insecure Direct Object Reference (IDOR) vulnerability in the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress. It affects all versions up to and including 3.7.0, allowing unauthenticated attackers to create arbitrary refund requests for any order ID and item ID without authorization. The vulnerability was published on February 10, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE, Feedly).

Technical details

The root cause is a Missing Authorization check (CWE-862) in the wcfm-refund-requests-form AJAX controller within the WCFM Marketplace plugin. Because the controller does not verify whether the requesting user is authorized to submit a refund for a given order or item, any unauthenticated HTTP request can supply arbitrary order IDs and item IDs to trigger refund creation. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker (Red Hat CVE, Infinitsec).

Impact

The primary impact is financial: if the WooCommerce store has automatic refund approval enabled in the plugin settings, unauthenticated attackers can trigger unauthorized refunds for any order, resulting in direct monetary loss for merchants. Integrity is partially affected (Low) as fraudulent refund records are injected into the system, while confidentiality and availability are not directly impacted. The scope is limited to the affected WordPress/WooCommerce installation, but the financial consequences can be significant for high-volume multivendor marketplaces (Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation campaigns have been confirmed for CVE-2026-1722 at this time. The EPSS score is approximately 0.048%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low barrier to exploitation (unauthenticated, network-accessible, no special tools required) means opportunistic abuse is plausible, particularly against stores with automatic refund approval enabled (Feedly, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WCFM Marketplace plugin version 3.7.0 or earlier using tools like WPScan, Shodan, or by inspecting plugin metadata in publicly accessible readme.txt files.
  2. Enumerate order IDs: Attempt to enumerate valid WooCommerce order IDs by observing order confirmation pages, email receipts, or by brute-forcing sequential order IDs via the WooCommerce REST API or storefront.
  3. Craft malicious AJAX request: Send an unauthenticated HTTP POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action parameter set to invoke the wcfm-refund-requests-form controller, supplying arbitrary order_id and item_id values.
  4. Submit refund request: The plugin processes the request without authorization checks, creating a refund request record in the database for the targeted order.
  5. Trigger automatic approval: If the store has automatic refund approval configured, the fraudulent refund is processed automatically, resulting in financial loss for the merchant (Infinitsec, Red Hat CVE).

Indicators of compromise

  • Network: Unusual or high-volume unauthenticated POST requests to /wp-admin/admin-ajax.php with parameters referencing wcfm-refund-requests-form from unexpected IP addresses.
  • Logs: WordPress/WooCommerce access logs showing repeated AJAX calls to the refund form endpoint without associated authenticated sessions; multiple refund requests for the same or sequential order IDs in a short timeframe.
  • Application: Unexpected refund request entries in the WCFM Marketplace admin panel, particularly for orders not initiated by the order owner; automated refund approvals for orders with no corresponding customer-initiated request.

Mitigation and workarounds

Administrators should update the WCFM Marketplace plugin to a version beyond 3.7.0, which includes the authorization fix for the wcfm-refund-requests-form AJAX controller. As an immediate workaround, disabling automatic refund approval in the plugin settings will prevent financial loss even if fraudulent refund requests are submitted. Additionally, restricting access to wp-admin/admin-ajax.php for unauthenticated users via a web application firewall (WAF) rule can reduce exposure (Red Hat CVE, Infinitsec).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management