A vulnerability was found in wcmp MultiVendorX Plugin up to 4.2.14 on WordPress. It has been classified as critical. Affected is an unknown function. The manipulation of the argument tabname leads to path traversal.
This vulnerability is traded as CVE-2025-0493. It is possible to launch the attack remotely. There is no exploit available.