CVE-2025-24706

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 79

Summary

CVE-2025-24706 is a Cross-Site Scripting (XSS) vulnerability affecting MultiVendorX WC Marketplace from versions n/a through 4.2.13. An attacker can exploit this Improper Neutralization of Input during web page generation issue to inject malicious scripts into a vulnerable page and steal user data or take control of their sessions. This stored XSS vulnerability poses a serious threat to the security of user browsing and transactions on the affected marketplace.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • WC Marketplace Plugin

Affected Vendors

  • WordPress