Extension WordPress
Vulnérabilités MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions, page 2
Cette page rassemble les failles publiées pour MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions
26 fiches
Multivendor Marketplace Solution for WooCommerce – WC Marketplace <= 3.8.11.8 – Local File Inclusion
The Multivendor Marketplace Solution for WooCommerce plugin is vulnerable to Local File Inclusion via the 'wcmp_announcements_refresh_tab_data' unprotected AJAX action in versions up to, and including, 3.8.11.8. This allows unauthenticated attackers to include arbitrary files on the local filesystem,…
*-3.8.11.8
3.8.12
15/08/2022
Multivendor Marketplace Solution for WooCommerce – WC Marketplace <= 3.8.11.8 – Reflected Cross-Site Scripting
The Multivendor Marketplace Solution for WooCommerce plugin is vulnerable to Reflected Cross-Site Scripting via multiple unprotected AJAX actions in versions up to, and including, 3.8.11.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
*-3.8.11.8
3.8.12
15/08/2022
Multivendor Marketplace Solution for WooCommerce – WC Marketplace <= 3.8.11.8 – Cross-Site Request Forgery
The Multivendor Marketplace Solution for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.11.8. This is due to missing or incorrect nonce validation on the wcmp_suspend_vendor ajax action. This makes…
*-3.8.11.8
3.8.12
04/08/2022
Multivendor Marketplace Solution for WooCommerce – WC Marketplace < 3.8.4 – Reflected Cross-Site Scripting
The Multivendor Marketplace Solution for WooCommerce – WC Marketplace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions before 3.8.4 due to insufficient input sanitization and output escaping. This makes it possible…
[*, 3.8.4)
3.8.4
06/12/2021
Multivendor Marketplace Solution for WooCommerce <= 3.7.3 – Insecure Direct Object Reference
The Multivendor Marketplace Solution for WooCommerce plugin for WordPress is vulnerable to users commenting as a different user in versions up to, and including, 3.7.3. This is due to improper user ID validation and and capability checking This…
*-3.7.3
3.7.4
26/05/2021
MultiVendorX – MultiVendor Marketplace Solution For WooCommerce <= 3.5.7 – Cross-Site Request Forgery Bypass
The MultiVendorX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.7. This is due to missing or incorrect nonce validation on the submit_comment() function. This makes it possible for unauthenticated attackers…
[*, 3.5.8)
3.5.8
16/09/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.