Pricing
WordPress securityInstantly fix and mitigate vulnerabilitiesPlugin auditingPaid auditing for WordPress vendorsManaged VDPStart a security program for your pluginsBug BountyJoin the community and earn bountiesEnterprise APIAt scale monitoring and vPatching for hostsVulnerability databaseThe latest WordPress security intelligence
Login Start trial
Plugin Icon

WCFM – Frontend Manager for WooCommerce

WC Lovers

Developer

6.7.22

Latest version

20,000

Installations

1 day ago

Last updated

WordPress Plugin
Active VDP
Report vulnerability
    VulnerabilitiesSecurity PolicySecurity Contributors

Vulnerability history

0 present
7 fixed
5 Mitigation rules
  • Missing Authorization to Unauthenticated Plugin Settings Modification vulnerability
    <= 6.7.16
    Jul 8, 2025
  • Insecure Direct Object Reference to Account Takeover/Privilege Escalation vulnerability
    <= 6.7.12
    Sep 25, 2024
  • Cross Site Scripting (XSS) vulnerability
    <= 6.7.8
    Mar 25, 2024
  • Missing Authorization vulnerability
    6.6.0
    Apr 6, 2023
  • Cross-Site Request Forgery vulnerability
    <= 6.5.13
    Apr 6, 2023
  • Unauthenticated SQL Injection (SQLi) vulnerability
    <= 6.6.1
    Feb 19, 2022
  • SQL Injection (SQLi) vulnerability
    <= 6.5.11
    Oct 11, 2021

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • Documentation
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2025 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag