CVE-2025-48261 Details
Description
Insertion of Sensitive Information Into Sent Data vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Retrieve Embedded Sensitive Data.This issue affects MultiVendorX: from n/a through <= 4.2.22.
A vulnerability allowing the retrieval of embedded sensitive data has been identified in the WordPress MultiVendorX plugin, affecting versions through 4.2.22. This issue arises from the improper handling of sensitive information, which can be accessed by users under certain conditions.
Users of the WordPress MultiVendorX plugin should update to version 4.2.23 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| multivendorx multivendorx | < 4.2.23 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 1, 2026 | CVE Modified | [email protected] |
| Jul 2, 2025 | Initial Analysis | [email protected] |
| Jun 9, 2025 | New CVE Received | [email protected] |