VYPR

MultiLoca

by WordPress

CVEs (2)

  • CVE-2024-13341MedFeb 1, 2025
    risk 0.42cvss 6.5epss 0.00

    The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and including, 4.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-39546Jun 17, 2026
    risk 0.00cvss epss 0.00

    Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.