Impact
The vulnerability is a Limited Local File Inclusion in the MultiVendorX WooCommerce Multivendor Marketplace plugin for WordPress. An unauthenticated attacker can supply a crafted value to the 'tabname' parameter of an AJAX endpoint, causing the server to include a local PHP file. This inclusion permits execution of arbitrary PHP code, enabling the attacker to bypass access controls, exfiltrate sensitive data, or fully compromise the site if executable files can be placed in the target directories.
Affected Systems
The affected product is the MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin, versions 4.2.14 and earlier (any version up to and including 4.2.14). This affects WordPress sites that have installed the plugin under that version range.
Risk and Exploitability
The CVSS score of 9.8 classifies the flaw as critical, and the EPSS score of less than 1% indicates that current exploit attempts are low. The flaw is listed as not in CISA KEV. Exploitation requires no authentication and can be achieved by sending a crafted 'tabname' value to the vulnerable AJAX endpoint. Successful exploitation allows an attacker to include and execute arbitrary PHP code, giving full control over the affected server.
OpenCVE Enrichment
EUVD