Home/Product/multivendorx
Product

multivendorx

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-48261
< 4.2.23
Insertion of Sensitive Information Into Sent Data vulnerability in MultiVendorX dc-woocommerce-multi-vendor allows Re
7.5HIGH
CVE-2025-48263
< 4.2.23
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX dc
6.5MEDIUM
CVE-2025-4101
< 4.2.23
The MultiVendorX - WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data d
4.3MEDIUM
CVE-2025-2789
< 4.2.20
The MultiVendorX - Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace - Build the Next Amazon, eBay, Etsy plugi
5.3MEDIUM
CVE-2025-0493
< 4.2.15
The MultiVendorX - The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local
9.8CRITICAL
CVE-2024-9943
< 4.2.5
The MultiVendorX - The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross-Site Requ
6.3MEDIUM
CVE-2024-9531
< 4.2.5
The MultiVendorX - The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized mo
4.3MEDIUM
CVE-2024-8289
< 4.2.1
The MultiVendorX - The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escal
9.8CRITICAL
CVE-2024-31304
< 4.1.4
Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.1.3.
7.1HIGH
CVE-2024-25929
< 5.0.6
Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX.This issue affects Pro
6.5MEDIUM
CVE-2024-5259
< 4.1.12
The MultiVendorX Marketplace - WooCommerce MultiVendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cross-Sit
6.4MEDIUM
CVE-2023-5348
< 5.0.3
The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape sett
6.1MEDIUM
CVE-2023-37972
< 2.0.2
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MultiVendorX Product Stock Manager & Notifier for WooC
5.3MEDIUM
CVE-2020-36741
<= 3.5.7
The MultiVendorX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.7. This is
4.3MEDIUM
threatengine.sh