Unknown WC Vendors
3 known vulnerabilities in Unknown WC Vendors, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-81428 CVSS 6.5 medium The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product…
- CVE-2026-81427 CVSS 4.3 medium The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns…
- CVE-2026-81426 CVSS 4.3 medium The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which…