The Multivendor Marketplace Solution for WooCommerce plugin is vulnerable to a type of cyber attack called Reflected Cross-Site Scripting in versions up to 3.8.11.8. This type of attack makes it possible for attackers to inject malicious web scripts into pages that can be executed if they can trick a user into taking an action, such as clicking a link.