Executive brief
WC Vendors Marketplace is a WordPress plugin that allows website owners to create a multi-vendor e-commerce platform similar to Etsy or eBay. A security flaw in this plugin allows logged-in users with basic 'Subscriber' accounts to execute unauthorized database commands. This could lead to the theft of sensitive customer data, exposure of site configuration details, or disruption of the marketplace's operations.
Technical details
A SQL injection vulnerability exists in the WC Vendors Marketplace plugin for WordPress in versions up to and including 2.6.8. The flaw is caused by improper neutralization of user-supplied input in SQL commands (CWE-89). An attacker with a minimum of 'Subscriber' level privileges can exploit this via a network request to interact directly with the underlying database. Successful exploitation can lead to unauthorized data exfiltration or limited impact on database availability. The issue is resolved in version 2.6.9.
Affected products
- Rymera Web Co WC Vendors Marketplace <= 2.6.8
Timeline
- 2026-05-08: other: Vulnerability reported by researcher hhhai
- 2026-06-18: advisory: Patchstack published advisory and mitigation rules
- 2026-06-25: disclosed: CVE published to NVD
- 2026-06-25: patched: Version 2.6.9 released to address the vulnerability