WC Vendors WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Unauthenticated Product Deletion

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WC Vendors WordPress plugin, specifically in the WooCommerce Multivendor, WooCommerce Marketplace, and Product Vendors versions up to and including 2.6.4. The vulnerability arises from inadequate nonce validation on the product deletion endpoint, which allows unauthenticated attackers to delete vendor products by tricking a site administrator into clicking a link.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of vendor products from the marketplace.

Remediation

Users are advised to update the WC Vendors plugin to version 2.6.4.1 or a newer patched version.

Added: Dec 5, 2025, 8:18 AM
Updated: Dec 5, 2025, 8:18 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
7.2
remediation
7.7
relevance
1.4
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.