MultiVendorX plugin vulnerable to Cross-Site Request Forgery
CVE-2024-9943
6.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 24 October 2024
What is CVE-2024-9943?
The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is affected by a Cross-Site Request Forgery (CSRF) vulnerability due to inadequate nonce validation in several functions of the api/class-mvx-rest-controller.php file. This flaw allows unauthenticated attackers to manipulate vendor account information and hinder user management processes. By tricking a site administrator into executing a forged request, attackers might update vendor account details, create new vendor accounts, and even delete arbitrary users. It is crucial for users of this plugin to apply the necessary updates to prevent potential exploitation.
Affected Version(s)
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution * <= 4.2.4