MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Arbitrary Vendor Deletion

2024-09-03 00:00
wesley (wcraft)

Vulnerability Overview

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to arbitrary vendor user deletion due to an insufficient capability check on the delete_item_permissions_check function in all versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to delete arbitrary users with the vendor role. This can be combined with CVE-2024-8289 to delete administrator accounts.

Technical Analysis

REMEDIATION: Update to version 4.2.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C