MultiVendorX 4.2.17 for WordPress

CPE Details

MultiVendorX 4.2.17 for WordPress
4.2.17
2025-06-05
15h54 +00:00
2025-06-05
15h54 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:multivendorx:multivendorx:4.2.17:*:*:*:*:wordpress:*:*

Informations

Vendor

multivendorx

Product

multivendorx

Version

4.2.17

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-48261 2025-06-09 15h53 +00:00 Insertion of Sensitive Information Into Sent Data vulnerability in MultiVendorX MultiVendorX allows Retrieve Embedded Sensitive Data. This issue affects MultiVendorX: from n/a through 4.2.22.
7.5
High
CVE-2025-48263 2025-05-19 14h45 +00:00 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX MultiVendorX allows Stored XSS. This issue affects MultiVendorX: from n/a through 4.2.22.
6.5
Medium
CVE-2025-4101 2025-05-17 12h22 +00:00 The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary posts, pages, attachments, and products. The vulnerability was partially patched in version 4.2.22.
4.3
Medium
CVE-2025-2789 2025-04-05 05h32 +00:00 The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shipping_row function in all versions up to, and including, 4.2.19. This makes it possible for unauthenticated attackers to delete Table Rates that can impact the shipping cost calculations.
6.5
Medium