CVE-2025-48261: WordPress MultiVendorX plugin <= 4.2.22 - Sensitive Data Exposure Vulnerability
Published Jun 9, 2025
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Retrieve Embedded Sensitive Data.This issue affects MultiVendorX: from n/a through <= 4.2.22.
Affected Software
1 affected component
MultiVendorX Multivendorx Wordpress<4.2.23
Remediation
Information
Update the WordPress MultiVendorX plugin to the latest available version (at least 4.2.23).
Event History
Jun 9, 2025
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48261?
CVE-2025-48261 is classified as a critical vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2025-48261?
To fix CVE-2025-48261, update MultiVendorX to version 4.2.23 or later.
3
What type of information does CVE-2025-48261 expose?
CVE-2025-48261 allows for the retrieval of embedded sensitive data within sent data.
4
Which versions of MultiVendorX are affected by CVE-2025-48261?
CVE-2025-48261 affects MultiVendorX versions prior to 4.2.23.
5
Who is affected by CVE-2025-48261?
Any users of MultiVendorX prior to version 4.2.23 may be affected by CVE-2025-48261.