Impact
The Vulnerable Dc Woocommerce Multi Vendor plugin allows an authenticated user with the 'edit_stores' capability to inject arbitrary SQL through the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse endpoint. Insufficient escaping and an unsanitized concatenation into an ORDER BY clause enable the attacker to append additional SQL statements, resulting in unauthorized data exfiltration from the database.
Affected Systems
Products from MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions are vulnerable. Versions up to and including 5.0.18 are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS data is reported, and the vulnerability is not listed in CISA's KEV catalog. The attack requires authentication with vendor-level privileges; once authenticated, the attacker can execute the injection to read database contents.
OpenCVE Enrichment