Post
CryptoCat
cryptocat.me
did:plc:kubwqlylxvsepe7y2rsjoeuo
Found an SQL injection in WCFM Marketplace, the WooCommerce multivendor plugin. A guest's checkout coordinates flow straight into a store-distance query, enough to read WordPress password hashes. CVE-2026-18442, fixed in 3.8.2, $134 bounty.
https://cryptocat.me/blog/research/analysis/cve_2026_18442/
2026-09-19T10:05:20.160Z