CVE-2025-4101: MultiVendorX – WooCommerce Multivendor Marketplace Solutions <= 4.2.22 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Post Deletion
The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'deletefpmproduct' function in all versions up to, and including, 4.2.22. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary posts, pages, attachments, and products. The vulnerability was partially patched in version 4.2.22.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4101?
CVE-2025-4101 has a severity rating that indicates a risk of unauthorized data loss due to a misconfiguration.
How do I fix CVE-2025-4101?
To fix CVE-2025-4101, update the MultiVendorX WooCommerce Multivendor Marketplace Solutions plugin to version 4.2.23 or later.
What versions of MultiVendorX are affected by CVE-2025-4101?
CVE-2025-4101 affects all versions of MultiVendorX WooCommerce Multivendor Marketplace Solutions up to and including version 4.2.22.
What kind of vulnerability is CVE-2025-4101?
CVE-2025-4101 is a vulnerability that leads to unauthorized loss of data due to a misconfigured capability check.
Who is impacted by CVE-2025-4101?
Users of the MultiVendorX WooCommerce Multivendor Marketplace Solutions plugin on WordPress are impacted by CVE-2025-4101.