WC Vendors – WooCommerce Multivendor
cpe:2.3:a:wcvendors:woocommerce_multi-vendor,_woocommerce_marketplace,_product_vendors:*:*:*:*:wordpress:*:*
- <= 2.6.4
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WC Vendors WordPress plugin, specifically in the WooCommerce Multivendor, WooCommerce Marketplace, and Product Vendors versions up to and including 2.6.4. The vulnerability arises from inadequate nonce validation on the product deletion endpoint, which allows unauthenticated attackers to delete vendor products by tricking a site administrator into clicking a link.
Exploitation of this vulnerability allows for unauthorized deletion of vendor products from the marketplace.
Users are advised to update the WC Vendors plugin to version 2.6.4.1 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.