Access violation vulnerability in Product Vendors 2.1.68

The WooCommerce Products Vendor plugin for WordPress is vulnerable to a security issue in certain versions. This issue allows vendors to change the commission percentage they get for sales. The vulnerable versions of the plugin are up to and including version 2.1.65. This security issue is caused by the plugin not properly checking the data it is given when updating the settings of its “wcpv-vendor-settings” page.

Detected in:

Product Vendors fixed vulnerable versions: >= * <= 2.1.68

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.