Impact
The vulnerability is an SQL injection flaw in the administrative portion of the WC Vendors Marketplace plugin for WordPress. The flaw allows a vulnerable party to inject malicious SQL statements that are executed by the back‑end database. Attackers could read, modify, or delete data in the plugin’s tables, potentially compromising the confidentiality, integrity, or availability of the e‑commerce site. The weakness corresponds to CWE-89, an improper input validation that permits injection of SQL commands.
Affected Systems
Affected products include the WC Vendors Marketplace plugin from WCVendors. Versions up to and including 2.7.2.1 are vulnerable. The plugin is widely deployed on WordPress installations that host multi‑vendor marketplaces.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. The EPSS score is not available, so the current probability of exploitation in the wild is unknown, but the lack of a KEV listing does not preclude enterprise impact. Exploitation likely requires an attacker to obtain administrative access to the WordPress admin area, and the attacker would then supply crafted input through the vulnerable endpoint. Once the injection succeeds, the attacker can fabricate arbitrary SQL to read or alter stored data.
OpenCVE Enrichment