CVE-2025-48261 PUBLISHED

WordPress MultiVendorX <= 4.2.22 - Sensitive Data Exposure Vulnerability

Assigner: Patchstack
Reserved: 19.05.2025 Published: 09.06.2025 Updated: 10.06.2025

Insertion of Sensitive Information Into Sent Data vulnerability in MultiVendorX MultiVendorX allows Retrieve Embedded Sensitive Data. This issue affects MultiVendorX: from n/a through 4.2.22.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor MultiVendorX
Product MultiVendorX
Versions Default: unaffected
  • affected from n/a to 4.2.22 (incl.)

Solutions

Update the WordPress MultiVendorX plugin to the latest available version (at least 4.2.23).

Credits

  • LVT-tholv2k (Patchstack Alliance) finder

References

Problem Types

  • CWE-201 Insertion of Sensitive Information Into Sent Data CWE

Impacts

  • CAPEC-37 Retrieve Embedded Sensitive Data