WooCommerce Multi Locations Inventory Management
by WordPress
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-9054 | Cri | 0.64 | 9.8 | 0.00 | Sep 24, 2025 | The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'wcmlim_settings_ajax_handler' function in all versions up to,… | ||
| CVE-2026-39546 | Hig | 0.49 | 7.6 | 0.00 | Jun 17, 2026 | Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions. | ||
| CVE-2024-13341 | Med | 0.42 | 6.5 | 0.00 | Feb 1, 2025 | The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and including, 4.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient… |
- risk 0.64cvss 9.8epss 0.00
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'wcmlim_settings_ajax_handler' function in all versions up to,…
- risk 0.49cvss 7.6epss 0.00
Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.
- risk 0.42cvss 6.5epss 0.00
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and including, 4.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient…