Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data.

This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
Published: 2026-07-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in MultiVendorX WooCommerce Product Stock Alert, allowing an attacker to read sensitive system information that should not be exposed. It is a classic data‑exposure flaw (CWE‑497) in which the plugin’s code incorrectly exposes internal details to users without proper authorization.

Affected Systems

All WordPress installations running any version of the MultiVendorX WooCommerce Product Stock Alert plugin up through 3.0.6 are affected, irrespective of other plugins or themes installed.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. The EPSS score (below 1%) suggests that exploit attempts are unlikely but still possible. The vulnerability is not listed in CISA’s KEV catalog. While the attack vector is not explicitly defined in the data, it is inferred from the description that it can be triggered via the plugin’s exposed data retrieval mechanisms, potentially through HTTP requests from an authenticated or even unauthenticated user. The impact is limited to information disclosure, but could aid further attack steps if combined with other weaknesses.

Generated by OpenCVE AI on August 3, 2026 at 21:36 UTC.

Remediation

Vendor Solution

Update the WordPress WooCommerce Product Stock Alert Plugin to the latest available version (at least 3.1.0).


OpenCVE Recommended Actions

  • Update the WooCommerce Product Stock Alert plugin to version 3.1.0 or newer, following the vendor’s upgrade instructions.
  • Purge any obsolete plugin files and configuration remnants from the WordPress filesystem to ensure the vulnerable code is fully removed.
  • If a patch cannot be applied immediately, temporarily disable the plugin or restrict it to administrators only to prevent further exposure of sensitive data.

Generated by OpenCVE AI on August 3, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Multivendorx
Multivendorx woocommerce Product Stock Alert
Wordpress
Wordpress wordpress
Vendors & Products Multivendorx
Multivendorx woocommerce Product Stock Alert
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
Title WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Multivendorx Woocommerce Product Stock Alert
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T15:26:43.238Z

Reserved: 2026-07-13T06:13:34.178Z

Link: CVE-2026-61945

cve-icon Vulnrichment

Updated: 2026-07-23T15:26:38.657Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:34.180

Modified: 2026-07-23T16:17:46.340

Link: CVE-2026-61945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:45:03Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere