MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Arbitrary Vendor Deletion
Strategic Overview
<= 4.2.0CVE-2024-8289Vulnerability Overview
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to arbitrary vendor user deletion due to an insufficient capability check on the delete_item_permissions_check function in all versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to delete arbitrary users with the vendor role. This can be combined with CVE-2024-8289 to delete administrator accounts.
Technical Analysis
REMEDIATION: Update to version 4.2.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C