CVE-2024-8289 affects the MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress. In all versions up to and including 4.2.0, the plugin performs insufficient capability checks in the update_item_permissions_check and create_item_permissions_check functions. As a result, unauthenticated attackers can invoke functionality that should be restricted to authorized users. The flaw allows attackers to change the password of arbitrary users with the vendor role, create new accounts with the vendor role, and change the role of other users, including demoting administrators to the vendor role. The issue is therefore both an authorization flaw and a privilege-management weakness that can lead to account takeover and unauthorized role modification.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit for CVE-2024-8289, targeting the MultiVendorX (formerly WCMP) plugin for WordPress. The exploit script (main.py) first checks if the vulnerable plugin is installed on the target site by attempting to access its readme.txt file. It then tries to determine the plugin version from either the readme.txt or the main plugin PHP file. If the version is found to be 4.2.0 or lower, the script attempts to exploit the vulnerability by sending a POST request to the /wp-json/wc/v3/vendors REST API endpoint, creating a new vendor account with attacker-supplied credentials. The exploit is operational and automates the process of detection, version checking, and exploitation. The only code file is main.py, written in Python, and the repository also includes a brief README.md describing the CVE and affected product. The exploit is not part of a framework and is a standalone script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.