The MultiVendorX plugin for WordPress has a security issue called Stored Cross-Site Scripting. This can happen in versions up to 4.2.22 because the plugin does not properly clean and protect the information it receives and displays. This means that attackers who have logged in and have contributor-level access or higher can add harmful web scripts to pages. These scripts will run whenever someone visits the affected page.