CVE-2020-36741: MultiVendorX – MultiVendor Marketplace Solution For WooCommerce <= 3.5.7 - Cross-Site Request Forgery Bypass
The MultiVendorX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.7. This is due to missing or incorrect nonce validation on the submitcomment() function. This makes it possible for unauthenticated attackers to submit comments via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-36741?
CVE-2020-36741 refers to a vulnerability in the MultiVendorX plugin for WordPress that allows for Cross-Site Request Forgery.
What is the severity of CVE-2020-36741?
CVE-2020-36741 has a severity level of medium with a severity value of 4.3.
How does CVE-2020-36741 affect the MultiVendorX plugin?
CVE-2020-36741 affects versions up to and including 3.5.7 of the MultiVendorX plugin for WordPress.
How can unauthenticated attackers exploit CVE-2020-36741?
Unauthenticated attackers can exploit CVE-2020-36741 by submitting comments via a forged request.
Is there a fix available for CVE-2020-36741?
Yes, an update to version 3.5.8 or later of the MultiVendorX plugin for WordPress fixes CVE-2020-36741.