Data Loss Vulnerability in MultiVendorX WooCommerce Plugin for WordPress
CVE-2025-4101
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 May 2025
What is CVE-2025-4101?
The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is susceptible to a significant security flaw that allows authenticated users with Contributor-level access and higher to delete posts, pages, attachments, and products. This vulnerability arises from a misconfigured capability check in the 'delete_fpm_product' function, exposing websites to potential unauthorized data loss. A partial patch has been implemented in version 4.2.22 to mitigate this issue, but prior versions remain vulnerable.
Affected Version(s)
MultiVendorX – WooCommerce Multivendor Marketplace Solutions * <= 4.2.22