MultiVendorX plugin vulnerable to Cross-Site Request Forgery
CVE-2024-9943

6.3MEDIUM

Key Information:

Summary

The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is affected by a Cross-Site Request Forgery (CSRF) vulnerability due to inadequate nonce validation in several functions of the api/class-mvx-rest-controller.php file. This flaw allows unauthenticated attackers to manipulate vendor account information and hinder user management processes. By tricking a site administrator into executing a forged request, attackers might update vendor account details, create new vendor accounts, and even delete arbitrary users. It is crucial for users of this plugin to apply the necessary updates to prevent potential exploitation.

Affected Version(s)

MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution * <= 4.2.4

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wesley
.