MultiVendorX 4.2.21 for WordPress

CPE Details

MultiVendorX 4.2.21 for WordPress
4.2.21
2025-06-05
15h54 +00:00
2025-06-05
15h54 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:multivendorx:multivendorx:4.2.21:*:*:*:*:wordpress:*:*

Informations

Vendor

multivendorx

Product

multivendorx

Version

4.2.21

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-48261 2025-06-09 15h53 +00:00 Insertion of Sensitive Information Into Sent Data vulnerability in MultiVendorX MultiVendorX allows Retrieve Embedded Sensitive Data. This issue affects MultiVendorX: from n/a through 4.2.22.
7.5
High
CVE-2025-48263 2025-05-19 14h45 +00:00 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX MultiVendorX allows Stored XSS. This issue affects MultiVendorX: from n/a through 4.2.22.
6.5
Medium
CVE-2025-4101 2025-05-17 12h22 +00:00 The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary posts, pages, attachments, and products. The vulnerability was partially patched in version 4.2.22.
4.3
Medium