CVE-2025-9054 affects the MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress, specifically versions up to and including 4.2.8. This critical vulnerability (CVSS 9.8) allows unauthenticated attackers to modify arbitrary WordPress options due to a missing capability check. Attackers can exploit this to enable user registration and set the default role to administrator, gaining full administrative access to the site. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Techspawn | MultiLoca - WooCommerce Multi Locations Inventory Management | >= 0, <= 4.2.8CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.