CVE-2024-9531: MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mvxsentdeactivationrequest' function in all versions up to, and including, 4.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send a canned email to the site's administrator asking to delete the profile of an arbitrary vendor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9531?
CVE-2024-9531 is classified as a critical vulnerability due to unauthorized data modification risks.
How do I fix CVE-2024-9531?
To fix CVE-2024-9531, update the MultiVendorX plugin to the latest version above 4.2.4 where the issue is resolved.
What versions are affected by CVE-2024-9531?
CVE-2024-9531 affects all versions of the MultiVendorX plugin up to and including version 4.2.4.
What does CVE-2024-9531 vulnerability impact?
CVE-2024-9531 impacts the integrity of the data in the MultiVendorX plugin, allowing unauthorized modifications.
Is there a workaround for CVE-2024-9531?
There is no official workaround for CVE-2024-9531; updating the plugin is the recommended solution.