What the vulnerability does
01Description
Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.2.
Explanation of Vulnerability in Simple Terms
02Summary
The Product Catalog Enquiry for WooCommerce plugin through version 5.0.2 lacks proper authorization checks on certain operations. An authenticated user with low privileges can modify or delete data they should not have access to. The vulnerability affects data integrity and availability but does not expose sensitive information.
What an attacker can do
03Attacker Capabilities
Modify or delete catalog data and enquiries without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can corrupt or remove product catalog enquiries and related data.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the WooCommerce site.
Key dates
06Disclosure timeline
December 9, 2024
CVE published
April 28, 2026
Record updated