Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 05 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wcvendors
Wcvendors woocommerce Multi-vendor, Woocommerce Marketplace, Product Vendors Wordpress Wordpress wordpress |
|
| Vendors & Products |
Wcvendors
Wcvendors woocommerce Multi-vendor, Woocommerce Marketplace, Product Vendors Wordpress Wordpress wordpress |
Fri, 05 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.4. This is due to missing or incorrect nonce validation on the /vendor_dashboard/product/delete/ endpoint. This makes it possible for unauthenticated attackers to delete vendor products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:29:03.861Z
Reserved: 2025-10-23T18:51:55.361Z
Link: CVE-2025-12130
Updated: 2025-12-05T12:54:25.271Z
Status : Deferred
Published: 2025-12-05T08:15:46.170
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-12130
No data.
OpenCVE Enrichment
Updated: 2026-04-21T17:45:16Z