CVE-2025-49916
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions
Minimum safe version
4.2.24
Update to 4.2.24 or later to address 36 fixable vulnerabilities
CVE-2025-48261
CVE-2025-48263
MultiVendorX – WooCommerce Multivendor Marketplace Solutions <= 4.2.22 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Post Deletion
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 - Missing Authorization to Unauthenticated Table Rates Deletion
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion
CVE-2025-24706
CVE-2024-9531
CVE-2024-9943
CVE-2024-8289
CVE-2024-43213
CVE-2024-5259
CVE-2024-31304
CVE-2024-30433
CVE-2024-24703
MultiVendorX < 4.0.26 - Improper Authorization on REST Routes via 'save_settings_permission'
WordPress WC Marketplace Plugin <= 4.0.23 is vulnerable to Broken Access Control
MultiVendorX <= 4.0.25 - Improper Authorization on REST Routes via 'save_settings_permission'
CVE-2020-36741
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
Multivendor Marketplace Solution for WooCommerce <= 3.7.3 - Insecure Direct Object Reference
Multivendor Marketplace Solution for WooCommerce – WC Marketplace < 3.8.4 - Reflected Cross-Site Scripting
Multivendor Marketplace Solution for WooCommerce – WC Marketplace <= 3.8.11.8 - Local File Inclusion
Multivendor Marketplace Solution for WooCommerce – WC Marketplace <= 3.8.11.8 - Reflected Cross-Site Scripting
Multivendor Marketplace Solution for WooCommerce < 3.7.4 - Unauthenticated Arbitrary Product Comment
Multivendor Marketplace Solution for WooCommerce < 3.8.4 - Reflected Cross-Site Scripting
Multivendor Marketplace Solution for WooCommerce < 3.8.12 - Unauthenticated LFI
Multivendor Marketplace Solution for WooCommerce < 3.8.12 - Multiple Reflected Cross-Site Scripting
CSRF Bypass in Multiple Plugins
WordPress WC Marketplace Plugin <= 3.8.11.8 - Reflected Cross-Site Scripting vulnerability
WordPress WC Marketplace Plugin <= 3.8.11.8 - Unauthenticated Local File Inclusion (LFI) vulnerability
CVE-2022-2657
WordPress WC Marketplace plugin <= 3.5.7 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress WC Marketplace plugin <= 3.7.3 - Unauthenticated Arbitrary Product Comment Posting vulnerability
WordPress WC Marketplace plugin <= 3.7.3 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress WC Marketplace plugin <= 3.8.4 - Reflected Cross-Site Scripting (XSS) vulnerability