CVE-2025-4101

The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary posts, pages, attachments, and products. The vulnerability was partially patched in version 4.2.22.
Configurations

Configuration 1 (hide)

cpe:2.3:a:multivendorx:multivendorx:*:*:*:*:*:wordpress:*:*

History

28 May 2025, 13:28

Type Values Removed Values Added
CPE cpe:2.3:a:multivendorx:multivendorx:*:*:*:*:*:wordpress:*:*
First Time Multivendorx multivendorx
Multivendorx
References () https://plugins.trac.wordpress.org/browser/dc-woocommerce-multi-vendor/trunk/classes/class-mvx-ajax.php#L982 - () https://plugins.trac.wordpress.org/browser/dc-woocommerce-multi-vendor/trunk/classes/class-mvx-ajax.php#L982 - Product
References () https://plugins.trac.wordpress.org/changeset/3293832/dc-woocommerce-multi-vendor/trunk/classes/class-mvx-ajax.php?old=3272848&old_path=dc-woocommerce-multi-vendor%2Ftrunk%2Fclasses%2Fclass-mvx-ajax.php - () https://plugins.trac.wordpress.org/changeset/3293832/dc-woocommerce-multi-vendor/trunk/classes/class-mvx-ajax.php?old=3272848&old_path=dc-woocommerce-multi-vendor%2Ftrunk%2Fclasses%2Fclass-mvx-ajax.php - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/5c1fd517-32ee-429d-9026-512afe117dc5?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/5c1fd517-32ee-429d-9026-512afe117dc5?source=cve - Third Party Advisory

19 May 2025, 13:35

Type Values Removed Values Added
Summary
  • (es) El complemento MultiVendorX – WooCommerce Multivendor Marketplace Solutions para WordPress es vulnerable a la pérdida no autorizada de datos debido a una comprobación de capacidad mal configurada en la función "delete_fpm_product" en todas las versiones hasta la 4.2.22 incluida. Esto permite a atacantes autenticados, con acceso de Colaborador o superior, eliminar entradas, páginas, archivos adjuntos y productos arbitrarios. La vulnerabilidad se corrigió parcialmente en la versión 4.2.22.

17 May 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-17 13:15

Updated : 2025-05-28 13:28


NVD link : CVE-2025-4101

Mitre link : CVE-2025-4101

CVE.ORG link : CVE-2025-4101


JSON object : View

Products Affected

multivendorx

  • multivendorx
CWE
CWE-863

Incorrect Authorization