
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49916 is a Missing Authorization (Broken Access Control) vulnerability in the MultiVendorX WordPress plugin (also known as dc-woocommerce-multi-vendor) that allows unauthenticated attackers to access functionality not properly constrained by ACLs. It affects all versions of the plugin through and including 4.2.23, with version 4.2.24 containing the fix. The vulnerability was reported by researcher Mika on May 13, 2025, and publicly disclosed on October 22, 2025. It carries a CVSS v3.1 base score of 8.6 (High), assigned by Patchstack (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning certain privileged or restricted plugin functions lack proper authorization checks before execution. This allows unauthenticated network-based attackers to invoke functionality that should be restricted to higher-privileged roles (e.g., vendor or administrator actions) within the WooCommerce multi-vendor marketplace environment. No user interaction or special configuration is required to exploit the flaw, as the attack vector is fully network-accessible with low complexity. Specific vulnerable endpoints or function names have not been publicly detailed beyond the Patchstack advisory (Patchstack).
Successful exploitation allows an unauthenticated attacker to perform privileged actions within the MultiVendorX plugin environment, resulting in high integrity impact (e.g., unauthorized modification of vendor or marketplace data), low confidentiality impact (potential exposure of sensitive information), and low availability impact. In a WooCommerce multi-vendor context, this could include unauthorized manipulation of product listings, vendor settings, orders, or other marketplace functionality, potentially disrupting business operations or enabling fraud (Patchstack).
The vulnerability requires no authentication and no user interaction, making it trivially exploitable by any remote attacker. Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. No specific public proof-of-concept exploit code has been identified, and the EPSS score is very low at approximately 0.017%, suggesting limited observed exploitation activity to date. There is no indication of CISA KEV catalog inclusion or confirmed in-the-wild exploitation at the time of disclosure (Patchstack).
/wp-content/plugins/dc-woocommerce-multi-vendor/readme.txt.wp-admin/admin-ajax.php with the target action parameter, or a REST API call) without authentication credentials, invoking the unprotected privileged function.wp-admin/admin-ajax.php with MultiVendorX-specific action parameters, or unusual REST API calls to /wp-json/ endpoints associated with the dc-woocommerce-multi-vendor plugin from unknown IP addresses.The vendor has released version 4.2.24 of the MultiVendorX plugin, which resolves this vulnerability; all users should update immediately. As an interim measure, Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. Site administrators unable to update immediately should consider temporarily deactivating the plugin or restricting access to the WordPress admin and AJAX endpoints via firewall rules (Patchstack).
Patchstack, the CNA that assigned and disclosed this CVE, classifies it as high priority and warns that broken access control vulnerabilities of this type are frequently leveraged in mass-exploit campaigns against WordPress sites. No notable independent researcher commentary, vendor statements beyond the patch release, or significant media coverage has been identified for this specific CVE (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."