CVE-2025-24706
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 24, 2025
CWE ID 79
Summary
CVE-2025-24706 is a Cross-Site Scripting (XSS) vulnerability affecting MultiVendorX WC Marketplace from versions n/a through 4.2.13. An attacker can exploit this Improper Neutralization of Input during web page generation issue to inject malicious scripts into a vulnerable page and steal user data or take control of their sessions. This stored XSS vulnerability poses a serious threat to the security of user browsing and transactions on the affected marketplace.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WC Marketplace Plugin
Affected Vendors
- WordPress