📦 Multivendorx

by Multivendorx

🔍 What is Multivendorx?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-0493

CRITICAL CVSS 9.8 Jan 31, 2025

This vulnerability allows unauthenticated attackers to perform local file inclusion via the tabname parameter in the MultiVendorX WordPress plugin. Attackers can include PHP files on the server, poten...

CVE-2024-8289

CRITICAL CVSS 9.8 Sep 4, 2024

This vulnerability in the MultiVendorX WordPress plugin allows unauthenticated attackers to perform privilege escalation and account takeover attacks. Attackers can change vendor passwords, create new...

CVE-2025-48261

HIGH CVSS 7.5 Jun 9, 2025

This vulnerability in MultiVendorX WordPress plugin allows attackers to retrieve embedded sensitive data that should not be exposed. It affects all WordPress sites using MultiVendorX plugin versions u...

CVE-2024-31304

HIGH CVSS 7.1 Jun 9, 2024

This CVE describes a Missing Authorization vulnerability in MultiVendorX WC Marketplace WordPress plugin. It allows unauthorized users to perform actions that should require proper authentication, aff...

CVE-2025-48263

MEDIUM CVSS 6.5 May 19, 2025

This stored cross-site scripting (XSS) vulnerability in MultiVendorX WordPress plugin allows attackers to inject malicious scripts into web pages that are then executed when other users view those pag...

CVE-2024-9531

MEDIUM CVSS 4.3 Oct 24, 2024

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to send unauthorized deactivation requests for arbitrary vendor profiles. Attackers can trigger canned em...