Description
The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up to and including 5.0.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query — the value is concatenated directly into an ORDER BY clause where esc_sql() (which only neutralizes characters needed to break out of quoted string literals) provides no protection. This makes it possible for authenticated attackers, with vendor-level access and above (users granted the 'edit_stores' capability), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published: 2026-10-02
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: SQL Injection allowing extraction of sensitive database information
Action: Patch Immediately
AI Analysis

Impact

The Vulnerable Dc Woocommerce Multi Vendor plugin allows an authenticated user with the 'edit_stores' capability to inject arbitrary SQL through the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse endpoint. Insufficient escaping and an unsanitized concatenation into an ORDER BY clause enable the attacker to append additional SQL statements, resulting in unauthorized data exfiltration from the database.

Affected Systems

Products from MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions are vulnerable. Versions up to and including 5.0.18 are affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. No EPSS data is reported, and the vulnerability is not listed in CISA's KEV catalog. The attack requires authentication with vendor-level privileges; once authenticated, the attacker can execute the injection to read database contents.

Generated by OpenCVE AI on October 2, 2026 at 08:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MultiVendorX plugin to version 5.0.19 or later.
  • Ensure the WordPress installation updates to the latest plugin release from the official repository.
  • If update is temporarily unavailable, remove or restrict the 'order_by' parameter from the REST endpoint or revoke the 'edit_stores' capability from all users except trusted administrators.

Generated by OpenCVE AI on October 2, 2026 at 08:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up to and including 5.0.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query — the value is concatenated directly into an ORDER BY clause where esc_sql() (which only neutralizes characters needed to break out of quoted string literals) provides no protection. This makes it possible for authenticated attackers, with vendor-level access and above (users granted the 'edit_stores' capability), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Title MultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:23.862Z

Reserved: 2026-06-22T20:45:34.984Z

Link: CVE-2026-12951

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:01.130

Modified: 2026-10-02T08:17:01.130

Link: CVE-2026-12951

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')