Extension WordPress
Vulnérabilités MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions
Cette page rassemble les failles publiées pour MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions
26 fiches
MultiVendorX <= 5.0.9 – Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter
The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 5.0.9 due to insufficient escaping on the user supplied…
*-5.0.9
5.0.10
15/07/2026
MultiVendorX <= 4.2.23 – Missing Authorization
The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.23. This makes it possible for unauthenticated…
*-4.2.23
4.2.24
12/06/2025
MultiVendorX <= 4.2.22 – Unauthenticated Information Exposure
The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.22. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
*-4.2.22
4.2.23
04/06/2025
MultiVendorX <= 4.2.22 – Authenticated (Contributor+) Stored Cross-Site Scripting
The MultiVendorX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-4.2.22
4.2.23
19/05/2025
MultiVendorX – WooCommerce Multivendor Marketplace Solutions <= 4.2.22 – Incorrect Authorization to Authenticated (Contributor+) Arbitrary Post Deletion
The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it…
*-4.2.22
4.2.23
16/05/2025
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 – Missing Authorization to Unauthenticated Table Rates Deletion
The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shipping_row…
*-4.2.19
4.2.20
04/04/2025
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 – Unauthenticated Limited Local File Inclusion
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possible for unauthenticated attackers…
*-4.2.14
4.2.15
30/01/2025
WC Marketplace <= 4.2.13 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WC Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-4.2.13
4.2.14
24/01/2025
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 – Missing Authorization to Forged Vendor Profile Deletion Email Sending
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mvx_sent_deactivation_request' function in all versions up to, and including, 4.2.4. This…
*-4.2.4
4.2.5
23/10/2024
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 – Cross-Site Request Forgery to Vendor Updates
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.4. This is due to missing or incorrect nonce validation on several functions…
*-4.2.4
4.2.5
23/10/2024
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 – Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escalation/de-escalation and account takeover due to an insufficient capability check on the update_item_permissions_check and create_item_permissions_check functions in all versions up to, and…
*-4.2.0
4.2.1
03/09/2024
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 – Missing Authorization to Arbitrary Vendor Deletion
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to arbitrary vendor user deletion due to an insufficient capability check on the delete_item_permissions_check function in all versions up to, and including, 4.2.0. This…
*-4.2.0
4.2.1
03/09/2024
WC Marketplace <= 4.1.17 – Reflected Cross-Site Scripting
The WC Marketplace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.1.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-4.1.17
4.2.0
09/08/2024
MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution <= 4.1.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter
The MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hover_animation’ parameter in all versions up to, and including, 4.1.11 due to insufficient input sanitization and output escaping. This…
*-4.1.11
4.1.12
05/06/2024
WC Marketplace <= 4.1.3 – Missing Authorization
The WC Marketplace plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform…
*-4.1.3
4.1.4
05/04/2024
WC Marketplace <= 4.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WC Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-4.1.3
4.1.4
28/03/2024
MultiVendorX Marketplace <= 4.0.25 – Missing Authorization
The MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in all versions up to, and including, 4.0.25. This makes it possible for unauthenticated…
*-4.0.25
4.0.26
31/01/2024
WC Marketplace <= 4.0.23 – Missing Authorization via mvx_save_dashpages
The WC Marketplace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mvx_save_dashpages' function in versions up to, and including, 4.0.23. This makes it possible for unauthenticated attackers to…
*-4.0.23
4.0.24
26/12/2023
MultiVendorX <= 4.0.25 – Improper Authorization on REST Routes via 'save_settings_permission'
The MultiVendorX plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on the 'save_settings_permission' function for the REST routes instantiated by the 'mvx_rest_routes_react_module' function…
[*, 4.0.26)
4.0.26
12/09/2023
Multivendor Marketplace Solution for WooCommerce – WC Marketplace <= 3.8.11.8 – Multiple Unprotected AJAX Actions
The Multivendor Marketplace Solution for WooCommerce plugin has multiple unprotected AJAX actions that lack capability or nonce checks in versions up to, and including, 3.8.11.8. This allows unauthenticated attackers to view and modify sensitive vendor information.
*-3.8.11.8
3.8.12
15/08/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.