Ultimate Multivendor Marketplace Plugin Vulnerable to Privilege Escalation and Account Takeover
CVE-2024-8289

9.8CRITICAL

Key Information:

Summary

The MultiVendorX plugin for WordPress enables users to manage multi-vendor marketplaces but suffers from vulnerabilities that allow for privilege escalation and account takeover. Specifically, insufficient capability checks in the update_item_permissions_check and create_item_permissions_check functions enable unauthenticated attackers to manipulate user accounts. Attackers can change the passwords of any user with a vendor role, create new users with vendor privileges, and demote existing users, including administrators, to the vendor role. This behavior presents a significant security risk for all users of the plugin prior to version 4.2.0.

Affected Version(s)

MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution * <= 4.2.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wesley
.