CVE-2025-48263: WordPress MultiVendorX plugin <= 4.2.22 - Cross Site Scripting (XSS) Vulnerability
Published May 19, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Stored XSS.This issue affects MultiVendorX: from n/a through <= 4.2.22.
Affected Software
3 affected components
MultiVendorX MultiVendorX<=4.2.22
WordPress MultiVendorX<=4.2.22
MultiVendorX Multivendorx Wordpress<4.2.23
Remediation
Information
Update the WordPress MultiVendorX plugin to the latest available version (at least 4.2.23).
Event History
May 19, 2025
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48263?
CVE-2025-48263 is a high-severity vulnerability that allows for stored cross-site scripting (XSS) in MultiVendorX.
2
How do I fix CVE-2025-48263?
To fix CVE-2025-48263, upgrade MultiVendorX to version 4.2.23 or later.
3
What are the potential impacts of CVE-2025-48263?
CVE-2025-48263 can lead to unauthorized access to user sessions and sensitive data due to stored XSS attacks.
4
Is my version of MultiVendorX affected by CVE-2025-48263?
Yes, MultiVendorX versions up to and including 4.2.22 are affected by CVE-2025-48263.
5
Which products are impacted by CVE-2025-48263?
CVE-2025-48263 impacts both MultiVendorX and the WordPress MultiVendorX Marketplace plugin up to version 4.2.22.