What the vulnerability does
01Description
Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.0.25.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
What the vulnerability does
Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.0.25.
Explanation of Vulnerability in Simple Terms
WC Marketplace versions up to 4.0.25 lack proper authorization checks, allowing unauthenticated attackers to modify marketplace data and settings. An attacker can change product information, vendor details, and site configuration without logging in. The vulnerability affects integrity and availability of the marketplace, potentially disrupting vendor operations and customer trust.
What an attacker can do
Modify marketplace data, vendor information, and site settings without authentication.
Potential impact on your site
Attackers can alter product listings, vendor accounts, and marketplace configuration, disrupting operations and data integrity.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities