A vulnerability, which was classified as problematic, was found in WCFM Marketplace Plugin up to 3.7.0 on WordPress. This impacts an unknown function of the component Refund Request Creation Handler. Executing a manipulation can lead to improper control of resource identifiers.
This vulnerability is handled as CVE-2026-1722. The attack can be executed remotely. There is not any exploit available.