WordPress MultiVendorX plugin <= 4.0.23 - Broken Access Control vulnerability
CVE-2023-51355
8.2HIGH
What is CVE-2023-51355?
The MultiVendorX WC Marketplace by Patchstack has a significant access control vulnerability due to missing authorization checks. This flaw allows attackers to exploit incorrectly configured access control security levels, enabling unauthorized access to sensitive functionality. This issue affects versions from n/a through 4.0.23, posing a risk to users who have not updated their plugins. Proper configuration and timely updates are crucial in mitigating such vulnerabilities to safeguard marketplace operations.
Affected Version(s)
WC Marketplace <= 4.0.23