Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
MultiVendorX
MultiVendorX
Developer
4.2.35
Latest version
4,000
Installations
Nov 4, 2025
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
22 fixed
12 Mitigation rules
Broken Access Control vulnerability
<= 4.2.23
Jun 12, 2025
Sensitive Data Exposure Vulnerability
<= 4.2.22
Jun 4, 2025
Cross Site Scripting (XSS) Vulnerability
<= 4.2.22
May 19, 2025
Missing Authorization to Unauthenticated Table Rates Deletion vulnerability
<= 4.2.19
Apr 4, 2025
Unauthenticated Limited Local File Inclusion vulnerability
<= 4.2.14
Jan 31, 2025
Cross Site Scripting (XSS) vulnerability
<= 4.2.13
Jan 24, 2025
Cross-Site Request Forgery to Vendor Updates vulnerability
<= 4.2.4
Oct 23, 2024
Missing Authorization to Forged Vendor Profile Deletion Email Sending vulnerability
<= 4.2.4
Oct 23, 2024
Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover vulnerability
<= 4.2.0
Sep 4, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 4.1.17
Aug 9, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter vulnerability
<= 4.1.11
Jun 6, 2024
Broken Access Control vulnerability
<= 4.1.3
Apr 5, 2024
Cross Site Scripting (XSS) vulnerability
<= 4.1.3
Mar 28, 2024
Broken Access Control vulnerability
<= 4.0.25
Jan 31, 2024
Broken Access Control vulnerability
<= 4.0.23
Dec 26, 2023
Unauthenticated Local File Inclusion (LFI) vulnerability
<= 3.8.11.8
Aug 15, 2022
Reflected Cross-Site Scripting vulnerability
<= 3.8.11.8
Aug 15, 2022
Unauthorized AJAX Calls Vulnerability
<= 3.8.11.8
Aug 15, 2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 3.8.4
Dec 6, 2021
Cross-Site Request Forgery (CSRF) vulnerability
<= 3.7.3
Jun 8, 2021
Unauthenticated Arbitrary Product Comment Posting vulnerability
<= 3.7.3
May 26, 2021
Cross-Site Request Forgery (CSRF) vulnerability
<= 3.5.7
Sep 16, 2020