CVE-2025-0493

CRITICAL CVSS 3.1: 9.8 EPSS 1.04%
Updated May 23, 2025
Multivendorx
Parameter Value
CVSS 9.8 (CRITICAL)
Affected Versions before 4.2.15
Fixed In 4.2.15
Type CWE-22 (Path Traversal)
Vendor Multivendorx
Public PoC No

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Multivendorx Multivendorx
cpe:2.3:a:multivendorx:multivendorx:*:*:*:*:*:wordpress:*:*
— 4.2.15