The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary posts, pages, attachments, and products. The vulnerability was partially patched in version 4.2.22.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 28 May 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Multivendorx Multivendorx multivendorx | |
| CPEs | cpe:2.3:a:multivendorx:multivendorx:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | Multivendorx Multivendorx multivendorx | 
Mon, 19 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Sat, 17 May 2025 12:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary posts, pages, attachments, and products. The vulnerability was partially patched in version 4.2.22. | |
| Title | MultiVendorX – WooCommerce Multivendor Marketplace Solutions <= 4.2.22 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Post Deletion | |
| Weaknesses | CWE-863 | |
| References |  | 
 | 
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Wordfence
Published: 2025-05-17T12:22:42.688Z
Updated: 2025-05-19T14:49:42.304Z
Reserved: 2025-04-29T18:54:24.866Z
Link: CVE-2025-4101
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-05-19T14:49:38.137Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-05-17T13:15:47.910
Modified: 2025-05-28T13:28:20.060
Link: CVE-2025-4101
 Redhat
                        Redhat
                    No data.