WC Marketplace is a plugin ecosystem for WooCommerce e-commerce platforms, consisting of a multivendor marketplace solution and catalog-inquiry functionality that extend WordPress-based storefronts. The observed vulnerability surface remains limited in scope, with structural exposure centered on the integration and data-handling demands of plugin-based marketplace architecture. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wc Marketplace over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-18592HIGH The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads. | Aug 27, 2019 | 7.5 | 24 | NO | NO |
CVE-2022-2657MEDIUM The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated | Sep 5, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wc Marketplace.
Media articles that mention a CVE ID that affects a product developed by Wc Marketplace — matched by CVE ID, not by vendor name.