Missing Authorization
12 records46.2%First: 2021. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 26 vulnerability records associated with MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions, published between 2020 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2020 | 1 | |
| 2021 | 2 | |
| 2022 | 4 | |
| 2023 | 2 | |
| 2024 | 9 | |
| 2025 | 7 | |
| 2026 | 1 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 7.7% |
| High | 7 | 26.9% |
| Medium | 17 | 65.4% |
First: 2021. Latest: 2025.
First: 2021. Latest: 2025.
First: 2020. Latest: 2024.
First: 2022. Latest: 2022.
First: 2025. Latest: 2025.
First: 2025. Latest: 2025.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
5.0.104.2.244.2.234.2.204.2.154.2.144.2.54.2.14.2.04.1.124.1.44.0.264.0.243.8.123.8.43.7.43.5.8Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-5.0.9 | MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter | July 15, 2026 | 5.0.10 | Medium |
*-4.2.23 | MultiVendorX <= 4.2.23 - Missing Authorization | June 12, 2025 | 4.2.24 | Medium |
*-4.2.22 | MultiVendorX <= 4.2.22 - Unauthenticated Information Exposure | June 4, 2025 | 4.2.23 | Medium |
*-4.2.22 | MultiVendorX <= 4.2.22 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 19, 2025 | 4.2.23 | Medium |
*-4.2.22 | MultiVendorX – WooCommerce Multivendor Marketplace Solutions <= 4.2.22 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Post Deletion | May 16, 2025 | 4.2.23 | Medium |
*-4.2.19 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 - Missing Authorization to Unauthenticated Table Rates Deletion | April 4, 2025 | 4.2.20 | Medium |
*-4.2.14 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion | January 30, 2025 | 4.2.15 | Critical |
*-4.2.13 | WC Marketplace <= 4.2.13 - Authenticated (Contributor+) Stored Cross-Site Scripting | January 24, 2025 | 4.2.14 | Medium |
*-4.2.4 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending | October 23, 2024 | 4.2.5 | Medium |
*-4.2.4 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates | October 23, 2024 | 4.2.5 | Medium |
*-4.2.0 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Arbitrary Vendor Deletion | September 3, 2024 | 4.2.1 | High |
*-4.2.0 | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover | September 3, 2024 | 4.2.1 | Critical |
*-4.1.17 | WC Marketplace <= 4.1.17 - Reflected Cross-Site Scripting | August 9, 2024 | 4.2.0 | Medium |
*-4.1.11 | MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter | June 5, 2024 | 4.1.12 | Medium |
*-4.1.3 | WC Marketplace <= 4.1.3 - Missing Authorization | April 5, 2024 | 4.1.4 | Medium |
*-4.1.3 | WC Marketplace <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | March 28, 2024 | 4.1.4 | Medium |
*-4.0.25 | MultiVendorX Marketplace <= 4.0.25 - Missing Authorization | January 31, 2024 | 4.0.26 | High |
*-4.0.23 | WC Marketplace <= 4.0.23 - Missing Authorization via mvx_save_dashpages | December 26, 2023 | 4.0.24 | High |
[*, 4.0.26) | MultiVendorX <= 4.0.25 - Improper Authorization on REST Routes via 'save_settings_permission' | September 12, 2023 | 4.0.26 | High |
*-3.8.11.8 | Multivendor Marketplace Solution for WooCommerce – WC Marketplace <= 3.8.11.8 - Multiple Unprotected AJAX Actions | August 15, 2022 | 3.8.12 | High |
*-3.8.11.8 | Multivendor Marketplace Solution for WooCommerce – WC Marketplace <= 3.8.11.8 - Local File Inclusion | August 15, 2022 | 3.8.12 | High |
*-3.8.11.8 | Multivendor Marketplace Solution for WooCommerce – WC Marketplace <= 3.8.11.8 - Reflected Cross-Site Scripting | August 15, 2022 | 3.8.12 | Medium |
*-3.8.11.8 | Multivendor Marketplace Solution for WooCommerce – WC Marketplace <= 3.8.11.8 - Cross-Site Request Forgery | August 4, 2022 | 3.8.12 | High |
[*, 3.8.4) | Multivendor Marketplace Solution for WooCommerce – WC Marketplace < 3.8.4 - Reflected Cross-Site Scripting | December 6, 2021 | 3.8.4 | Medium |
*-3.7.3 | Multivendor Marketplace Solution for WooCommerce <= 3.7.3 - Insecure Direct Object Reference | May 26, 2021 | 3.7.4 | Medium |
Selected source records
Published: July 15, 2026
Published: June 12, 2025
Published: June 4, 2025
Published: May 19, 2025
Published: May 16, 2025
Published: April 4, 2025
Published: January 30, 2025
Published: January 24, 2025
Published: January 30, 2025
Published: September 3, 2024
Published: August 4, 2022
Published: January 31, 2024
Published: September 12, 2023
Published: August 15, 2022
Published: December 26, 2023
Published: September 3, 2024
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.