CRITICAL 9.3 CVE-2026-81286 Published 2 Sept 2026

WCFM Marketplace SQL Injection

Worried this affects one of your servers?

WCFM Marketplace, a WordPress plugin, is affected by an unauthenticated SQL Injection vulnerability in versions up to 3.8.1.

This flaw allows attackers to inject malicious SQL queries, potentially leading to data theft or manipulation.

Reference: CVE-2026-81286 on NVD

← Back to Security News