What the vulnerability does
01Description
Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.1.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.1.3.
Explanation of Vulnerability in Simple Terms
WC Marketplace through version 4.1.3 lacks proper authorization checks, allowing authenticated users with low privileges to modify site data and disrupt service availability. An attacker with a basic user account can trigger actions that should be restricted to administrators or vendors. No confidentiality breach occurs, but integrity and availability are compromised.
What an attacker can do
Modify site data and cause service disruption with a low-privilege user account.
Potential impact on your site
Unauthorized users can alter marketplace data and cause downtime; requires immediate patching to prevent abuse.
Conditions required to exploit
Attacker must have a valid user account with low privileges; no special user interaction required.
Key dates
External resources
Related vulnerabilities