CVE-2024-9943: MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.4. This is due to missing or incorrect nonce validation on several functions in api/class-mvx-rest-controller.php. This makes it possible for unauthenticated attackers to update vendor account details, create vendor accounts, and delete arbitrary users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9943?
CVE-2024-9943 is classified as a Cross-Site Request Forgery vulnerability, which can allow unauthorized actions to be performed on behalf of users.
How do I fix CVE-2024-9943?
To fix CVE-2024-9943, update the MultiVendorX plugin for WordPress to version 4.2.5 or later, which includes the necessary nonce validation.
What versions are affected by CVE-2024-9943?
CVE-2024-9943 affects all versions of the MultiVendorX plugin for WordPress up to and including version 4.2.4.
What kind of attack can CVE-2024-9943 lead to?
CVE-2024-9943 can lead to unauthorized actions being executed on behalf of legitimate users, compromising their accounts.
Is there a patch available for CVE-2024-9943?
Yes, a patch is available in the updated version 4.2.5 of the MultiVendorX plugin that addresses the vulnerability.