MultiLoca <= 4.2.15 - Authenticated (Subscriber+) Privilege Escalation
high
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.2.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
- CVSS:
- 8.8
- Affected:
- up to 4.2.15
- Fixed in:
- 4.2.16
- Disclosed:
- Apr 8, 2026
CVE-2026-39546 on NVD →
MultiLoca - WooCommerce Multi Locations Inventory Management <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Options Update via 'wcmlim_settings_ajax_handler'
critical
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'wcmlim_settings_ajax_handler' function in all versions up to, and including, 4.2.8. This makes it possi...
- CVSS:
- 9.8
- Affected:
- up to 4.2.8
- Fixed in:
- 4.2.9
- Disclosed:
- Sep 23, 2025
CVE-2025-9054 on NVD →
MultiLoca - WooCommerce Multi Locations Inventory Management <= 4.1.11 - Authenticated (Subscriber+) SQL Injection
medium
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and including, 4.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This ma...
- CVSS:
- 6.5
- Affected:
- up to 4.1.11
- Fixed in:
- 4.1.12
- Disclosed:
- Jan 31, 2025
CVE-2024-13341 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database