CVE-2025-9054

MultiLoca - WooCommerce Multi Locations Inventory Management <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Options Update via 'wcmlim_settings_ajax_handler'

The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'wcmlim_settings_ajax_handler' function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.


We have discovered 84 live websites that are affected by CVE-2025-9054.

Run a Free Instant Scan




Affected Software

Product  WooCommerce Multi Locations Inventory Management
Category Wordpress Plugins
Vulnerable Domains84 live websites (100% of WooCommerce Multi Locations Inventory Management install base)
Vulnerable Versions
  • from 0 through 4.2.8
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Sep 24, 2025
  • Updated - Sep 24, 2025

Credits

  • Thái An (finder)

Website Distribution by Country

Number of websites using CVE-2025-9054
United States27 websites



Canada6 websites
Chile5 websites
Australia4 websites
France4 websites
Indonesia4 websites
South Africa4 websites
Russia3 websites
Belgium2 websites
Italy2 websites

Website Distribution by TLD

Number of websites using CVE-2025-9054
.com37 websites
.eu6 websites
.ca3 websites
.com.au3 websites
.ru2 websites
.be1 websites
.co.uk1 websites
.com.br1 websites
.cz1 websites
.fr1 websites

Websites affected by CVE-2025-9054

Top websites that are affected by CVE-2025-9054. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United States**,***
******.com United States***,***
***************.com United States*,***,***
**********.com United States*,***,***
***************.com Canada*,***,***
**************.com United States*,***,***
******.com Germany*,***,***
***********.com United States*,***,***
********.cc Belgium*,***,***
*******.com United States*,***,***
See full domain list

FAQ

CVE-2025-9054 is Missing Authorization in WooCommerce Multi Locations Inventory Management
A total of 84 websites have been identified as vulnerable to CVE-2025-9054, based on global website indexing conducted by WebTechSurvey.
The WooCommerce Multi Locations Inventory Management is affected by the CVE-2025-9054 vulnerability.
WooCommerce Multi Locations Inventory Management versions up to and including 4.2.8 are vulnerable to CVE-2025-9054.