MultiVendorX 5.0.13 - 5.0.14 - Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · MultiVendorXpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/c81aa489-0663-40b7-b2ce-f4c8f2edd4b6/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.