A popular plugin for WordPress called MultiVendorX has a security issue that affects all versions up to 4.2.4. This means that hackers can trick website administrators into making changes to vendor accounts or even deleting user accounts. This is due to a missing security check in the plugin’s code.