PT-2026-60400 · WordPress · Multivendorx
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions versions prior to 5.0.10
Description
An issue exists where insufficient escaping of user-supplied input and lack of query preparation allow authenticated attackers with subscriber-level access and above to perform SQL Injection. This occurs via the
order by parameter in the transactions endpoint. Attackers can append additional SQL queries to extract sensitive information from the database. This is particularly exploitable when the store approval setting is configured to automatically approve store owners, as any logged-in user can self-register as a store owner via the public Stores REST endpoint to obtain the necessary edit stores capability.Recommendations
Update MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions to version 5.0.10 or later.
Restrict the use of the
order by parameter in the transactions endpoint as a temporary mitigation.
Disable the automatic approval of store owners in the plugin settings to prevent unauthorized users from obtaining the edit stores capability.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multivendorx