SecAlerts
m

multivendorx

Security Risk Profile

49
/100
medium

Security Risk Score

Comprehensive risk assessment based on 23 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from July 1, 2023 to present

23
Total CVEs
10
Critical+High
0
Exploited
5
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
5
Critical/High
Risk Level
49/100
medium
🆕 1Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
3
High
7
Medium
11
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
8

Age Distribution

Common Weaknesses (CWE)

1
XSS
6
2
CSRF
2
3
Path Traversal
1
4
Infoleak
1

Most Affected Products

1. MultiVendorX Multivendorx Wordpress11
2. MultiVendorX MultiVendorX3
3. MultiVendorX WordPress plugin2
4. WordPress MultiVendorX2
5. MultiVendorX WC Marketplace2

Recent Vulnerabilities

See more →
CVE-2026-74927
unknown

MultiVendorX 5.0.13 - 5.0.14 - Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint

Sep 2, 2026🔧 No Patch
CVE-2026-16746
CVSS 2.7low

MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint

Aug 5, 2026🔧 No Patch
CVE-2026-16605
CVSS 7.2high

MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization

Aug 5, 2026🔧 No Patch
CVE-2025-49916
CVSS 8.6high

WordPress MultiVendorX plugin <= 4.2.23 - Broken Access Control vulnerability

Oct 22, 2025🔧 No Patch
CVE-2025-48261
CVSS 7.5high

WordPress MultiVendorX plugin <= 4.2.22 - Sensitive Data Exposure Vulnerability

Jun 9, 2025
CVE-2025-48263
CVSS 6.5EPSS 0%medium

WordPress MultiVendorX plugin <= 4.2.22 - Cross Site Scripting (XSS) Vulnerability

May 19, 2025
CVE-2025-4101
CVSS 4.3medium

MultiVendorX – WooCommerce Multivendor Marketplace Solutions <= 4.2.22 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Post Deletion

May 17, 2025
CVE-2025-2789
CVSS 6.5medium

MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 - Missing Authorization to Unauthenticated Table Rates Deletion

Apr 5, 2025🔧 No Patch
CVE-2025-0493
CVSS 9.8critical

MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion

Jan 31, 2025🔧 No Patch
CVE-2025-24706
CVSS 6.5EPSS 0%medium

WordPress MultiVendorX plugin <= 4.2.13 - Cross Site Scripting (XSS) vulnerability

Jan 24, 2025

Monitor multivendorx in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

multivendorx Security Vulnerabilities & Risk Score | 23 CVEs | SecAlerts - SecAlerts