CVE-2026-77701

NONE
Updated Aug 28, 2026
WordPress
Parameter Value
Affected Versions before 3.8.2
Vendor WordPress
Public PoC No

The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.