PT-2026-60400 · WordPress · Multivendorx

·

CVE-2026-12941

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions versions prior to 5.0.10
Description An issue exists where insufficient escaping of user-supplied input and lack of query preparation allow authenticated attackers with subscriber-level access and above to perform SQL Injection. This occurs via the order by parameter in the transactions endpoint. Attackers can append additional SQL queries to extract sensitive information from the database. This is particularly exploitable when the store approval setting is configured to automatically approve store owners, as any logged-in user can self-register as a store owner via the public Stores REST endpoint to obtain the necessary edit stores capability.
Recommendations Update MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions to version 5.0.10 or later. Restrict the use of the order by parameter in the transactions endpoint as a temporary mitigation. Disable the automatic approval of store owners in the plugin settings to prevent unauthorized users from obtaining the edit stores capability.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12941

Affected Products

Multivendorx