| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-49916 | WordPress MultiVendorX plugin <= 4.2.23 - Broken Access Control vulnerability | MultiVendorX | MultiVendorX | High | 8.6 | 2025-10-22 14:32:12 | Deep Dive |
| CVE-2025-48261 | WordPress MultiVendorX plugin <= 4.2.22 - Sensitive Data Exposure Vulnerability | MultiVendorX | MultiVendorX | - | - | 2025-06-09 15:53:56 | Deep Dive |
| CVE-2025-48263 | WordPress MultiVendorX plugin <= 4.2.22 - Cross Site Scripting (XSS) Vulnerability | MultiVendorX | MultiVendorX | Medium | 6.5 | 2025-05-19 14:45:12 | Deep Dive |
| CVE-2025-4101 | MultiVendorX – WooCommerce Multivendor Marketplace Solutions <= 4.2.22 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Post Deletion | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace Solutions | Medium | 4.3 | 2025-05-17 12:22:43 | Deep Dive |
| CVE-2025-2789 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 - Missing Authorization to Unauthenticated Table Rates Deletion | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace Solutions | Medium | 5.3 | 2025-04-05 05:32:14 | Deep Dive |
| CVE-2025-0493 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace Solutions | Critical | 9.8 | 2025-01-31 04:21:47 | Deep Dive |
| CVE-2025-24706 | WordPress MultiVendorX plugin <= 4.2.13 - Cross Site Scripting (XSS) vulnerability | MultiVendorX | MultiVendorX | Medium | 6.5 | 2025-01-24 17:25:03 | Deep Dive |
| CVE-2023-37971 | WordPress WooCommerce Product Stock Alert plugin <= 2.0.1 - Broken Access Control vulnerability | MultiVendorX | WooCommerce Product Stock Alert | Medium | 6.5 | 2024-12-13 14:23:51 | Deep Dive |
| CVE-2023-50899 | WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 5.0.2 - Broken Access Control vulnerability | MultiVendorX | Product Catalog Enquiry for WooCommerce by MultiVendorX | Medium | 5.4 | 2024-12-09 11:29:54 | Deep Dive |
| CVE-2023-51355 | WordPress MultiVendorX plugin <= 4.0.23 - Broken Access Control vulnerability | MultiVendorX | MultiVendorX | 高危 | - | 2024-12-09 11:29:50 | Deep Dive |
| CVE-2024-9943 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace Solutions | Medium | 6.3 | 2024-10-24 07:35:57 | Deep Dive |
| CVE-2024-9531 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace Solutions | Medium | 4.3 | 2024-10-24 07:35:56 | Deep Dive |
| CVE-2024-8289 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace Solutions | Critical | 9.8 | 2024-09-04 08:30:39 | Deep Dive |
| CVE-2024-43213 | WordPress MultiVendorX Marketplace plugin <= 4.1.17 - Reflected Cross Site Scripting (XSS) vulnerability | MultiVendorX | WC Marketplace | High | 7.1 | 2024-08-12 21:40:49 | Deep Dive |
| CVE-2024-24703 | WordPress MultiVendorX plugin <= 4.0.25 - Broken Access Control vulnerability | MultiVendorX | WC Marketplace | High | 8.6 | 2024-06-11 14:54:06 | Deep Dive |
| CVE-2024-31304 | WordPress MultiVendorX Marketplace <= 4.1.3 - Broken Access Control vulnerability | MultiVendorX | WC Marketplace | High | 7.1 | 2024-06-09 18:09:28 | Deep Dive |
| CVE-2024-25929 | WordPress Product Catalog Mode For Woocommerce plugin <= 5.0.5 - Broken Access Control vulnerability | MultiVendorX | Product Catalog Enquiry for WooCommerce by MultiVendorX | Medium | 6.5 | 2024-06-09 10:30:17 | Deep Dive |
| CVE-2024-5259 | MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace Solutions | Medium | 6.4 | 2024-06-06 09:34:02 | Deep Dive |
| CVE-2024-30433 | WordPress MultiVendorX Marketplace plugin <= 4.1.3 - Cross Site Scripting (XSS) vulnerability | MultiVendorX | WC Marketplace | Medium | 6.5 | 2024-03-29 17:29:28 | Deep Dive |
| CVE-2023-37972 | WordPress WooCommerce Product Stock Alert Plugin <= 2.0.1 is vulnerable to Sensitive Data Exposure | MultiVendorX | Product Stock Manager & Notifier for WooCommerce | Medium | 5.3 | 2023-11-30 15:07:39 | Deep Dive |