MultiLoca
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-13341 | Med | 0.42 | 6.5 | 0.00 | Feb 1, 2025 | The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and including, 4.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2026-39546 | 0.00 | — | 0.00 | Jun 17, 2026 | Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions. |
- risk 0.42cvss 6.5epss 0.00
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and including, 4.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- CVE-2026-39546Jun 17, 2026risk 0.00cvss —epss 0.00
Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.