Description
The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.4. This is due to missing or incorrect nonce validation on the /vendor_dashboard/product/delete/ endpoint. This makes it possible for unauthenticated attackers to delete vendor products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2025-12-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Deletion of Vendor Products
Action: Patch
AI Analysis

Impact

The WC Vendors plugin for WordPress is vulnerable to a Cross‑Site Request Forgery flaw (CWE‑352) that allows an unauthenticated attacker to delete vendor products. The flaw exists because the /vendor_dashboard/product/delete/ endpoint does not validate the required nonce, so a forged request can be accepted. If an attacker can convince a site administrator to click a crafted link or image, any vendor product can be removed, potentially causing loss of catalog items, revenue loss, and reputational damage.

Affected Systems

All installations of the WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin with version 2.6.4 or earlier are affected. The vulnerability is specific to the product deletion path on the vendor dashboard and applies to the WordPress site configured with this plugin.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The flaw is not listed in the CISA KEV catalog. The likely attack path requires the attacker to get an administrator or another privileged user to click a malicious link that triggers a delete request without a valid nonce. Because the request can be performed from a third‑party site, the core risk is the potential loss of vendor inventory and associated revenue. Mitigation is most effectively achieved by upgrading the plugin or implementing proper nonce validation.

Generated by OpenCVE AI on April 21, 2026 at 17:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WC Vendors plugin to version 2.6.5 or later to obtain the fixed CSRF protection.
  • Ensure that all delete requests to /vendor_dashboard/product/delete/ validate a correct nonce before processing the deletion.
  • Configure a web‑application firewall to detect and block incoming requests to the delete endpoint that lack the required nonce or contain suspicious query parameters.
  • Educate site administrators to avoid clicking unknown links and to verify URLs before actioning them.

Generated by OpenCVE AI on April 21, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Wcvendors
Wcvendors woocommerce Multi-vendor, Woocommerce Marketplace, Product Vendors
Wordpress
Wordpress wordpress
Vendors & Products Wcvendors
Wcvendors woocommerce Multi-vendor, Woocommerce Marketplace, Product Vendors
Wordpress
Wordpress wordpress

Fri, 05 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.4. This is due to missing or incorrect nonce validation on the /vendor_dashboard/product/delete/ endpoint. This makes it possible for unauthenticated attackers to delete vendor products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wcvendors Woocommerce Multi-vendor, Woocommerce Marketplace, Product Vendors
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:29:03.861Z

Reserved: 2025-10-23T18:51:55.361Z

Link: CVE-2025-12130

cve-icon Vulnrichment

Updated: 2025-12-05T12:54:25.271Z

cve-icon NVD

Status : Deferred

Published: 2025-12-05T08:15:46.170

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-12130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T17:45:16Z

Weaknesses