CVE-2025-49916
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-49916 is a Missing Authorization (Broken Access Control) vulnerability in the MultiVendorX WordPress plugin (also known as dc-woocommerce-multi-vendor) that allows unauthenticated attackers to access functionality not properly constrained by ACLs. It affects all versions of the plugin through and including 4.2.23, with version 4.2.24 containing the fix. The vulnerability was reported by researcher Mika on May 13, 2025, and publicly disclosed on October 22, 2025. It carries a CVSS v3.1 base score of 8.6 (High), assigned by Patchstack (Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning certain privileged or restricted plugin functions lack proper authorization checks before execution. This allows unauthenticated network-based attackers to invoke functionality that should be restricted to higher-privileged roles (e.g., vendor or administrator actions) within the WooCommerce multi-vendor marketplace environment. No user interaction or special configuration is required to exploit the flaw, as the attack vector is fully network-accessible with low complexity. Specific vulnerable endpoints or function names have not been publicly detailed beyond the Patchstack advisory (Patchstack).

Impact

Successful exploitation allows an unauthenticated attacker to perform privileged actions within the MultiVendorX plugin environment, resulting in high integrity impact (e.g., unauthorized modification of vendor or marketplace data), low confidentiality impact (potential exposure of sensitive information), and low availability impact. In a WooCommerce multi-vendor context, this could include unauthorized manipulation of product listings, vendor settings, orders, or other marketplace functionality, potentially disrupting business operations or enabling fraud (Patchstack).

Exploitability

The vulnerability requires no authentication and no user interaction, making it trivially exploitable by any remote attacker. Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. No specific public proof-of-concept exploit code has been identified, and the EPSS score is very low at approximately 0.017%, suggesting limited observed exploitation activity to date. There is no indication of CISA KEV catalog inclusion or confirmed in-the-wild exploitation at the time of disclosure (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the MultiVendorX plugin (version ≤ 4.2.23) using tools like WPScan, Shodan, or by checking publicly accessible plugin metadata at /wp-content/plugins/dc-woocommerce-multi-vendor/readme.txt.
  2. Identify unprotected endpoints: Enumerate REST API routes or AJAX actions registered by the MultiVendorX plugin that lack capability checks or nonce verification, targeting actions typically restricted to vendors or administrators.
  3. Craft unauthorized request: Send a crafted HTTP request (e.g., a POST to wp-admin/admin-ajax.php with the target action parameter, or a REST API call) without authentication credentials, invoking the unprotected privileged function.
  4. Achieve unauthorized action: Successfully execute the restricted functionality — such as modifying vendor data, product listings, or marketplace settings — without holding the required role or permission (Patchstack).

Indicators of compromise

  • Network: Unexpected unauthenticated POST requests to wp-admin/admin-ajax.php with MultiVendorX-specific action parameters, or unusual REST API calls to /wp-json/ endpoints associated with the dc-woocommerce-multi-vendor plugin from unknown IP addresses.
  • Logs: WordPress access logs showing repeated requests to plugin AJAX handlers or REST endpoints without valid authentication cookies or nonce tokens; anomalous activity in WooCommerce order or vendor logs.
  • File System: Unexpected changes to vendor product listings, settings, or marketplace configuration files that cannot be attributed to legitimate user activity.
  • Application: Unexplained modifications to vendor accounts, product data, or order statuses within the MultiVendorX dashboard (Patchstack).

Mitigation and workarounds

The vendor has released version 4.2.24 of the MultiVendorX plugin, which resolves this vulnerability; all users should update immediately. As an interim measure, Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. Site administrators unable to update immediately should consider temporarily deactivating the plugin or restricting access to the WordPress admin and AJAX endpoints via firewall rules (Patchstack).

Community reactions

Patchstack, the CNA that assigned and disclosed this CVE, classifies it as high priority and warns that broken access control vulnerabilities of this type are frequently leveraged in mass-exploit campaigns against WordPress sites. No notable independent researcher commentary, vendor statements beyond the patch release, or significant media coverage has been identified for this specific CVE (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18044NONEN/A
  • estatik
NoYesAug 12, 2026
CVE-2026-17008NONEN/A
  • quick-paypal-payments
NoNoAug 12, 2026
CVE-2026-16990NONEN/A
  • wp-paypal
NoNoAug 12, 2026
CVE-2026-16747NONEN/A
  • kirki
NoYesAug 12, 2026
CVE-2026-16621NONEN/A
  • woo-paypal-gateway
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management