The MultiVendorX plugin for WordPress is vulnerable to a type of attack known as Cross-Site Request Forgery. This is present in all versions up to, and including, 3.5.7. The issue is caused by incorrect or missing validation of a security feature called a ‘nonce’ on the submit_comment() function. This means that unauthenticated attackers can submit comments if they can get a site administrator to click on a malicious link.