Impact
An incorrect privilege assignment vulnerability in the MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX allows unprivileged users to perform actions reserved for higher‑level users or modify site data, affecting all versions up to 6.1.5. This can compromise the confidentiality, integrity, and availability of the WordPress site by enabling unauthorized data creation, modification, or configuration changes.
Affected Systems
WordPress sites using the MultiVendorX Product Catalog Enquiry for WooCommerce plugin version 6.1.5 or earlier are affected. Site administrators and owners of affected installations should verify the plugin version.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability, and the EPSS score of 0.00332 (about 0.33%) indicates a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can trigger the flaw by sending unauthenticated requests to the plugin’s endpoints, but they still require network access to the target site. Overall, the risk is moderate and warrants timely remediation.
OpenCVE Enrichment