MultiVendorX
MultiVendorX converts WooCommerce stores into multi-vendor marketplaces with vendor management, product listings, commissions, and order handling.
MultiVendorX (dc-woocommerce-multi-vendor) is a WordPress plugin with 20 published CVE records in this archive. The latest tracked vulnerability was published Sep 16, 2026; the highest published CVSS base score is 9.8.
dc-woocommerce-multi-vendorCVE-2026-74926: MultiVendorX lets subscribers overwrite another store's ownership and payouts
MultiVendorX from 5.0.0 up to but not including 5.0.16: Any authenticated user, including a Subscriber, can act on a selected store through a REST route that does not verify ownership. Attacker-controlled updates can replace store details, payout settings and the recorded owner. The export does not name the route, store selector or writable field names; theft of an actual payout is not independently established.
| Safe version |
|
||
|---|---|---|---|
| Sep 16, 2026 |
CVE-2026-74926
MultiVendorX lets subscribers overwrite another store's ownership and payouts
MultiVendorX from 5.0.0 up to but not including 5.0.16: Any authenticated user, including a Subscriber, can act on a selected store through a REST route that does not verify ownership. Attacker-controlled updates can replace store details, payout settings and the recorded owner. The export does not name the route, store selector or writable field names; theft of an actual payout is not independently established.
|
5.0.16 |
CVE7.1
NVDPending
|
| Sep 02, 2026 |
CVE-2026-74927
MultiVendorX exposes vendor payout and application data
MultiVendorX 5.0.13 and 5.0.14 does not authorize one REST API listing route. An unauthenticated visitor can retrieve vendor contact details, payout details, pending payout amounts, and administrative notes attached to store applications.
|
5.0.15 |
CVE5.3
NVDPending
|
| Aug 18, 2026 |
CVE-2026-66651
MultiVendorX: Broken access control
MultiVendorX is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.0.14.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 13, 2026 |
CVE-2026-66441
MultiVendorX: Broken access control
MultiVendorX is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.0.10.
|
5.0.11 |
CVE7.5
NVDPending
|
| Jul 16, 2026 |
CVE-2026-12941
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions: SQL injection
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.0.9.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 22, 2025 |
CVE-2025-49916
MultiVendorX: A security weakness
MultiVendorX is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.6
NVDPending
|
| May 17, 2025 |
CVE-2025-4101
MultiVendorX – WooCommerce Multivendor Marketplace Solutions: A security weakness
MultiVendorX – WooCommerce Multivendor Marketplace Solutions is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 05, 2025 |
CVE-2025-2789
Next Amazon, eBay, Etsy: A security weakness
Next Amazon, eBay, Etsy is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD6.5
|
| Jan 31, 2025 |
CVE-2025-0493
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution: Filesystem traversal
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Jan 24, 2025 |
CVE-2025-24706
MultiVendorX: Cross-site scripting
MultiVendorX is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 09, 2024 |
CVE-2023-51355
MultiVendorX: A security weakness
MultiVendorX is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.2
NVDPending
|
| Oct 24, 2024 |
CVE-2024-9943
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution: Cross-site request forgery
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.3
NVDPending
|
| Oct 24, 2024 |
CVE-2024-9531
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution: A security weakness
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 04, 2024 |
CVE-2024-8289
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution: Privilege escalation or authentication bypass
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 12, 2024 |
CVE-2024-43213
WC Marketplace: Cross-site scripting
WC Marketplace is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Jun 11, 2024 |
CVE-2024-24703
WC Marketplace: A security weakness
WC Marketplace is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.6
NVDPending
|
| Jun 09, 2024 |
CVE-2024-31304
WC Marketplace: A security weakness
WC Marketplace is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.1
NVD8.8
|
| Jun 06, 2024 |
CVE-2024-5259
MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution: Cross-site scripting
MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 29, 2024 |
CVE-2024-30433
WC Marketplace: Cross-site scripting
WC Marketplace is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jul 01, 2023 |
CVE-2020-36741
MultiVendorX: Cross-site request forgery
MultiVendorX is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|