Executive brief
WC Vendors Marketplace is a WordPress plugin that allows vendors to manage their storefronts on WooCommerce sites. An SQL injection vulnerability in versions 2.7.2.1 and earlier allows authenticated administrators to read, modify, or delete database contents, including user accounts and sensitive customer data, potentially compromising the entire online store.
Technical details
The vulnerability is a SQL injection flaw in the WC Vendors Marketplace WordPress plugin affecting versions up to 2.7.2.1. It requires administrator-level privileges to exploit, meaning it is restricted to users with high-level site access. An attacker with admin rights can inject malicious SQL queries through the vulnerable code path to read, modify, or delete database records. The patch is available in version 2.7.2.2 and later.
Affected products
- Rymera Web Co WC Vendors Marketplace <=2.7.2.1
Timeline
- 2026-09-08: disclosed: Reported to Patchstack
- 2026-09-17: advisory: Published by Patchstack and NVD
- 2026-09-17: patched: Patch available in version 2.7.2.2