CVE-2025-49916: WordPress MultiVendorX plugin <= 4.2.23 - Broken Access Control vulnerability
Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MultiVendorX: from n/a through <= 4.2.23.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49916?
CVE-2025-49916 is classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive functionalities.
How do I fix CVE-2025-49916?
To fix CVE-2025-49916, update MultiVendorX to version 4.2.24 or later, where the access control issues have been resolved.
What software versions are affected by CVE-2025-49916?
CVE-2025-49916 affects MultiVendorX versions from n/a through 4.2.23.
What type of vulnerability is CVE-2025-49916?
CVE-2025-49916 is a missing authorization vulnerability that allows access to functionalities not properly constrained by access control lists.
Who is impacted by CVE-2025-49916?
Users of the MultiVendorX plugin for WordPress up to version 4.2.23 are impacted by CVE-2025-49916.