Vulnerabilidades en wcmp

9 resultados
Análisis Vexday

A wcmp apresenta um perfil de risco modesto com 9 vulnerabilidades totais na base, sendo 2 críticas, mas nenhuma sob exploração ativa registrada (KEV). A fraqueza predominante é CWE-352 (CSRF - Cross-Site Request Forgery), indicando deficiências em proteção contra requisições falsificadas; o risco atual é mitigado pela baixa atividade recente, com apenas 1 CVE publicado nos últimos 90 dias.

CVE-2024-8289CRITICALMultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account TakeoverEPSS 1.3%CVE-2025-0493CRITICALMultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File InclusionEPSS 1.0%CVE-2026-12941MEDIUMMultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' ParameterEPSS 0.4%CVE-2020-36741MEDIUMMultiVendorX – MultiVendor Marketplace Solution For WooCommerce <= 3.5.7 - Cross-Site Request Forgery BypassEPSS 0.4%CVE-2025-2789MEDIUMMultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 - Missing Authorization to Unauthenticated Table Rates DeletionEPSS 0.4%CVE-2024-9531MEDIUMMultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email SendingEPSS 0.3%CVE-2024-5259MEDIUMMultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation ParameterEPSS 0.3%CVE-2025-4101MEDIUMMultiVendorX – WooCommerce Multivendor Marketplace Solutions <= 4.2.22 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Post DeletionEPSS 0.3%CVE-2024-9943MEDIUMMultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor UpdatesEPSS 0.2%