CVE-2023-5348: Multivendorx Product Catalog Mode For Woocommerce
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.
Affected products
- Multivendorx Product Catalog Mode For Woocommerce: before 5.0.3 (fixed in 5.0.3)
Published 2023-12-18. Last modified 2026-06-17.