CVE-2025-12130: WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion
The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.4. This is due to missing or incorrect nonce validation on the /vendordashboard/product/delete/ endpoint. This makes it possible for unauthenticated attackers to delete vendor products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12130?
CVE-2025-12130 is classified as a high severity vulnerability due to the risk of Cross-Site Request Forgery attacks.
How do I fix CVE-2025-12130?
To remediate CVE-2025-12130, upgrade the WC Vendors plugin to version 2.6.5 or higher where the issue has been addressed.
What versions are affected by CVE-2025-12130?
CVE-2025-12130 affects all versions of WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, and Product Vendors up to and including 2.6.4.
What is Cross-Site Request Forgery related to CVE-2025-12130?
Cross-Site Request Forgery in CVE-2025-12130 allows attackers to execute unauthorized actions on behalf of logged-in users.
What plugins are impacted by CVE-2025-12130?
The plugins impacted by CVE-2025-12130 include WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, and Product Vendors.