CVE-2026-18442

CVE-2026-18442 published: The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to insufficient escaping on the user supp...

View full NVD advisory → ← Back to CVE watch