CVE-2025-4101

The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary posts, pages, attachments, and products. The vulnerability was partially patched in version 4.2.22.
Configurations

Configuration 1 (hide)

cpe:2.3:a:multivendorx:multivendorx:*:*:*:*:*:wordpress:*:*

History

28 May 2025, 13:28

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-17 13:15

Updated : 2025-05-28 13:28


NVD link : CVE-2025-4101

Mitre link : CVE-2025-4101

CVE.ORG link : CVE-2025-4101


JSON object : View

Products Affected

multivendorx

  • multivendorx
CWE
CWE-863

Incorrect Authorization