CRITICAL
9.3 CVE-2026-81286 Published 2 Sept 2026
WCFM Marketplace SQL Injection
Worried this affects one of your servers?
WCFM Marketplace, a WordPress plugin, is affected by an unauthenticated SQL Injection vulnerability in versions up to 3.8.1.
This flaw allows attackers to inject malicious SQL queries, potentially leading to data theft or manipulation.
Reference: CVE-2026-81286 on NVD
← Back to Security News