Junglewise Threat Intelligence

CVE-2026-61945: MultiVendorX WooCommerce Product Stock Alert sensitive data exposure

CVE-2026-61945 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Vendors: MultiVendorX.

Executive brief

A vulnerability in the WooCommerce Product Stock Alert plugin for WordPress allows logged-in users with low-level permissions to access sensitive system information. This could lead to the exposure of internal data that is normally restricted, potentially aiding attackers in further compromising the website. Business operations may be impacted if confidential configuration or system details are leaked to unauthorized parties.

Technical details

The MultiVendorX WooCommerce Product Stock Alert plugin for WordPress (versions up to and including 3.0.6) is vulnerable to 'Exposure of Sensitive System Information to an Unauthorized Control Sphere' (CWE-497). This vulnerability allows an authenticated attacker with low-level privileges, such as a Subscriber, to retrieve sensitive data embedded within the system's control sphere. The attack is reachable over the network and does not require user interaction. The issue is addressed in version 3.1.0 of the plugin.

Affected products

  • MultiVendorX WooCommerce Product Stock Alert up to 3.0.6

Timeline

  • 2026-03-23: other: Reported by Jakub Herman
  • 2026-07-16: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD

References