Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-3780


The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcfm_redirect_to_setup function in all versions up to, and including, 6.7.16. This makes it possible for unauthenticated attackers to view and modify the plugin settings, including payment details and API keys


Published

2025-07-09T00:15:39.570

Last Modified

2025-07-17T13:34:21.007

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application wclovers frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible < 6.7.17 Yes

References