Sceawere
Vulnerability Detail
CVE-2026-12951UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dc Woocommerce Multi Vendor SQL Injection
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 15h ago
- Vendor
- wcmp
- Product
- MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up to and including 5.0.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query — the value is concatenated directly into an ORDER BY clause where esc_sql() (which only neutralizes characters needed to break out of quoted string literals) provides no protection. This makes it possible for authenticated attackers, with vendor-level access and above (users granted the 'edit_stores' capability), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-02T08:17:01.130Z",
"pubdate": "2026-10-02T08:17:01.130Z",
"executiveSummary": "The Dc Woocommerce Multi Vendor plugin is susceptible to an authenticated SQL injection vulnerability within its REST API implementation. Identified in versions up to and including 5.0.18, the flaw exists within the /multivendorx/v1/compliance/report-abuse endpoint.\nThe vulnerability arises from improper handling of the 'order_by' query parameter. An attacker with vendor-level privileges or higher (possessing the 'edit_stores' capability) can manipulate this input to perform unauthorized database queries. By injecting malicious SQL syntax directly into the application's backend database operations, a threat actor can circumvent existing security controls.\nThe impact of this vulnerability is significant, as it allows for the extraction of sensitive database information. Because the input is concatenated directly into the query, the security mechanism employed—specifically esc_sql()—is insufficient for ORDER BY clauses, as it only addresses string literal escaping. This creates a critical risk of data exfiltration and potential compromise of the WordPress database. Successful exploitation requires the attacker to be authenticated, limiting the attack surface to registered users with sufficient store management permissions.",
"technicalDetails": "The vulnerability resides in the backend processing logic of the /multivendorx/v1/compliance/report-abuse REST API endpoint. Specifically, the 'order_by' parameter is accepted as user-supplied input without proper validation or sanitization prior to its inclusion in a database query.\nThe root cause is a failure to utilize parameterized queries or strict allow-listing for dynamic SQL construction. The application performs a direct concatenation of the 'order_by' parameter into the ORDER BY clause of a SQL statement. The implementation mistakenly relies on esc_sql() to sanitize this input. While esc_sql() is effective for escaping string literals to prevent breaking out of single or double quotes, it provides no protection against SQL injection within an ORDER BY clause. Since an attacker can influence the column name or syntax in an ORDER BY context, they can append secondary SQL commands using techniques such as UNION-based injection or time-based blind SQL injection.\nThe attack flow requires an attacker to authenticate with at least 'edit_stores' capabilities. Upon reaching the endpoint, the attacker crafts a malicious request by injecting SQL fragments into the 'order_by' parameter. For example, by inputting a payload that closes the intended query and appends additional logic, the attacker forces the database to execute arbitrary commands under the privileges of the WordPress database user.\nBecause the vulnerable component functions as part of the MultiVendorX compliance reporting module, the exploitation allows the attacker to retrieve data from tables they would not otherwise have access to, potentially including user credentials, store configurations, and sensitive customer information. The lack of preparation in the SQL query means the database engine executes the attacker-supplied SQL instructions as part of the legitimate query execution context.\nThe vulnerability is present in versions 5.0.18 and earlier. The exposure is strictly limited to authenticated users; however, given the nature of multi-vendor plugins where vendor registration may be accessible, the privilege threshold is relatively low. The post-exploitation impact includes unauthorized data exfiltration, database structure reconnaissance, and potentially broader system compromise depending on the database user's underlying permissions."
}