MultiVendorX plugin vulnerable to Cross-Site Request Forgery
CVE-2024-9943
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 24 October 2024
Summary
The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is affected by a Cross-Site Request Forgery (CSRF) vulnerability due to inadequate nonce validation in several functions of the api/class-mvx-rest-controller.php file. This flaw allows unauthenticated attackers to manipulate vendor account information and hinder user management processes. By tricking a site administrator into executing a forged request, attackers might update vendor account details, create new vendor accounts, and even delete arbitrary users. It is crucial for users of this plugin to apply the necessary updates to prevent potential exploitation.
Affected Version(s)
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution * <= 4.2.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved