← WordPress Vulnerabilities
WordPress security by component

WC Vendors Marketplace

WC Vendors Marketplace transforms WooCommerce stores into multivendor marketplaces with vendor product and commission management.

WC Vendors Marketplace (wc-vendors) is a WordPress plugin with 8 published CVE records in this archive. The latest tracked vulnerability was published Sep 17, 2026; the highest published CVSS base score is 8.5.

Plugin slug: wc-vendors

CVE-2026-66625: WC Vendors Marketplace permits SQL injection with Administrator access

WC Vendors Marketplace through 2.7.2.1 has an SQL-injection flaw requiring Administrator access according to the CNA description. The disclosed class is attacker-influenced input being interpreted as part of an SQL command; the export does not identify the input parameter, endpoint, handler, query or encoding, so the exact path cannot be established. The CNA vector indicates high confidentiality impact and limited availability impact, without user interaction; it does not establish database modification or operating-system code execution. The affected-version data marks 2.7.2.2 unaffected.

PublishedSep 17, 2026
Known safe version2.7.2.2
Published vulnerabilities for wc-vendors
Safe version
Sep 17, 2026 CVE-2026-66625
WC Vendors Marketplace permits SQL injection with Administrator access
WC Vendors Marketplace through 2.7.2.1 has an SQL-injection flaw requiring Administrator access according to the CNA description. The disclosed class is attacker-influenced input being interpreted as part of an SQL command; the export does not identify the input parameter, endpoint, handler, query or encoding, so the exact path cannot be established. The CNA vector indicates high confidentiality impact and limited availability impact, without user interaction; it does not establish database modification or operating-system code execution. The affected-version data marks 2.7.2.2 unaffected.
2.7.2.2
CVE7.6
NVDPending
Sep 02, 2026 CVE-2026-81428
WC Vendors permits cross-vendor product and post modification
WC Vendors before 2.7.2.1 does not verify ownership or object type when saving user-supplied product-variation IDs. An authenticated vendor can modify another vendor's variations and can change the status and title of arbitrary posts.
2.7.2.1
CVE6.5
NVDPending
Sep 02, 2026 CVE-2026-81427
WC Vendors permits cross-vendor shipment-status manipulation
WC Vendors before 2.7.2.1 does not verify that a vendor owns the order referenced by a front-end shipment-status request. Any authenticated vendor can mark another vendor's order as shipped, add a note falsely attributed to that vendor, and trigger a customer shipment email.
2.7.2.1
CVE4.3
NVDPending
Sep 02, 2026 CVE-2026-81426
WC Vendors: Cross-site request forgery
WC Vendors is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is < 2.7.2.1.
2.7.2.1
CVE4.3
NVDPending
Aug 16, 2026 CVE-2026-15351
WC Vendors REST status parameter permits Shop Manager SQL injection
WC Vendors through 2.7.0 accepts a Shop Manager-controlled status value through its REST API and uses it in SQL without adequate preparation. sanitize_text_field() removes HTML but not SQL metacharacters, and the REST server unslashes GET parameters before sanitization. A Shop Manager can therefore append SQL and extract sensitive database information. The public.
2.7.1
CVE4.9
NVDPending
Jun 25, 2026 CVE-2026-54838
WC Vendors Marketplace: SQL injection
WC Vendors Marketplace is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.6.8.
2.6.9
CVE8.5
NVDPending
Jun 06, 2025 CVE-2025-49263
WC Vendors Marketplace: SQL injection
WC Vendors Marketplace is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
Dec 19, 2023 CVE-2023-48327
WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors: SQL injection
WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2