MultiVendorX <= 4.0.25 - Improper Authorization on REST Routes via 'save_settings_permission'
Strategic Overview
< 4.0.26N/AVulnerability Overview
The MultiVendorX plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on the 'save_settings_permission' function for the REST routes instantiated by the 'mvx_rest_routes_react_module' function versions up to, and including, 4.0.25. This makes it possible for unauthenticated attackers to create, update, and delete vendors, retrieve sensitive information, and modify plugin settings.
Technical Analysis
REMEDIATION: Update to version 4.0.26, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C