CVE-2025-54004: Wc Lovers Wcfm – Frontend Manager For Woocommerce

Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce wc-frontend-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM – Frontend Manager for WooCommerce: from n/a through <= 6.7.24.

Affected products

  • Wc Lovers Wcfm – Frontend Manager For Woocommerce: up to and including 6.7.24

Published 2025-12-16. Last modified 2026-10-07.