WC Vendors Marketplace
WC Vendors Marketplace transforms WooCommerce stores into multivendor marketplaces with vendor product and commission management.
WC Vendors Marketplace (wc-vendors) is a WordPress plugin with 8 published CVE records in this archive. The latest tracked vulnerability was published Sep 17, 2026; the highest published CVSS base score is 8.5.
wc-vendorsCVE-2026-66625: WC Vendors Marketplace permits SQL injection with Administrator access
WC Vendors Marketplace through 2.7.2.1 has an SQL-injection flaw requiring Administrator access according to the CNA description. The disclosed class is attacker-influenced input being interpreted as part of an SQL command; the export does not identify the input parameter, endpoint, handler, query or encoding, so the exact path cannot be established. The CNA vector indicates high confidentiality impact and limited availability impact, without user interaction; it does not establish database modification or operating-system code execution. The affected-version data marks 2.7.2.2 unaffected.
| Safe version |
|
||
|---|---|---|---|
| Sep 17, 2026 |
CVE-2026-66625
WC Vendors Marketplace permits SQL injection with Administrator access
WC Vendors Marketplace through 2.7.2.1 has an SQL-injection flaw requiring Administrator access according to the CNA description. The disclosed class is attacker-influenced input being interpreted as part of an SQL command; the export does not identify the input parameter, endpoint, handler, query or encoding, so the exact path cannot be established. The CNA vector indicates high confidentiality impact and limited availability impact, without user interaction; it does not establish database modification or operating-system code execution. The affected-version data marks 2.7.2.2 unaffected.
|
2.7.2.2 |
CVE7.6
NVDPending
|
| Sep 02, 2026 |
CVE-2026-81428
WC Vendors permits cross-vendor product and post modification
WC Vendors before 2.7.2.1 does not verify ownership or object type when saving user-supplied product-variation IDs. An authenticated vendor can modify another vendor's variations and can change the status and title of arbitrary posts.
|
2.7.2.1 |
CVE6.5
NVDPending
|
| Sep 02, 2026 |
CVE-2026-81427
WC Vendors permits cross-vendor shipment-status manipulation
WC Vendors before 2.7.2.1 does not verify that a vendor owns the order referenced by a front-end shipment-status request. Any authenticated vendor can mark another vendor's order as shipped, add a note falsely attributed to that vendor, and trigger a customer shipment email.
|
2.7.2.1 |
CVE4.3
NVDPending
|
| Sep 02, 2026 |
CVE-2026-81426
WC Vendors: Cross-site request forgery
WC Vendors is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is < 2.7.2.1.
|
2.7.2.1 |
CVE4.3
NVDPending
|
| Aug 16, 2026 |
CVE-2026-15351
WC Vendors REST status parameter permits Shop Manager SQL injection
WC Vendors through 2.7.0 accepts a Shop Manager-controlled status value through its REST API and uses it in SQL without adequate preparation. sanitize_text_field() removes HTML but not SQL metacharacters, and the REST server unslashes GET parameters before sanitization. A Shop Manager can therefore append SQL and extract sensitive database information. The public.
|
2.7.1 |
CVE4.9
NVDPending
|
| Jun 25, 2026 |
CVE-2026-54838
WC Vendors Marketplace: SQL injection
WC Vendors Marketplace is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.6.8.
|
2.6.9 |
CVE8.5
NVDPending
|
| Jun 06, 2025 |
CVE-2025-49263
WC Vendors Marketplace: SQL injection
WC Vendors Marketplace is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVDPending
|
| Dec 19, 2023 |
CVE-2023-48327
WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors: SQL injection
WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|