Unauthorized Data Deletion in MultiVendorX WooCommerce Plugin for WordPress
CVE-2025-2789
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 April 2025
What is CVE-2025-2789?
The MultiVendorX plugin for WooCommerce contains a vulnerability that permits unauthorized users to delete critical shipping rate data due to a missing capability check in the delete_table_rate_shipping_row function. This oversight can negatively affect shipping calculations, leading to possible disruptions in order processing and fulfillment for eCommerce platforms utilizing this plugin. Affected versions are up to and including 4.2.19.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MultiVendorX β Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace β Build the Next Amazon, eBay, Etsy * <= 4.2.19
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved