CVE-2025-48261 PUBLISHED

WordPress MultiVendorX plugin <= 4.2.22 - Sensitive Data Exposure Vulnerability

Assigner: Patchstack
Reserved: 19.05.2025 Published: 09.06.2025 Updated: 29.04.2026

Insertion of Sensitive Information Into Sent Data vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Retrieve Embedded Sensitive Data.This issue affects MultiVendorX: from n/a through <= 4.2.22.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor MultiVendorX
Product MultiVendorX
Versions Default: unaffected
  • affected from 0 to 4.2.22 (incl.)

Credits

  • LVT-tholv2k | Patchstack Bug Bounty Program finder

References

Problem Types

  • Insertion of Sensitive Information Into Sent Data CWE

Impacts

  • Retrieve Embedded Sensitive Data