CVE-2026-12941

MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter

The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 5.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This vulnerability is exploitable by any authenticated subscriber-level user when the plugin's store approval setting is configured to automatically approve store owners (described as the default), as this allows any logged-in user to self-register as a store_owner via the public Stores REST endpoint, thereby obtaining the edit_stores capability required to reach the vulnerable transactions endpoint.


We have discovered 309 live websites that are affected by CVE-2026-12941.

Run a Free Instant Scan




Affected Software

Product  Dc Woocommerce Multi Vendor
Category Wordpress Plugins
Vulnerable Domains309 live websites (100% of Dc Woocommerce Multi Vendor install base)
Vulnerable Versions
  • from 0 through 5.0.9
Vulnerable Versions Count54 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 16, 2026
  • Updated - Jul 16, 2026

Credits

  • PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-12941
United States107 websites



France24 websites
Germany19 websites
Cyprus16 websites
GB11 websites
India9 websites
Brazil8 websites
Italy8 websites
Russia7 websites
South Africa7 websites

Website Distribution by TLD

Number of websites using CVE-2026-12941
.com173 websites
.net10 websites
.fr9 websites
.com.br7 websites
.org6 websites
.it6 websites
.nl5 websites
.co.uk5 websites
.ru5 websites
.de3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12941

Top websites that are affected by CVE-2026-12941. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.**.il Israel**,***
***.com United States***,***
**********.com Malaysia***,***
*************.info GB***,***
*****************.**.uk United States***,***
**********.com United States*,***,***
****************.com India*,***,***
************.com France*,***,***
***************.com France*,***,***
**********************.fr France*,***,***
See full domain list

FAQ

CVE-2026-12941 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Dc Woocommerce Multi Vendor
A total of 309 websites have been identified as vulnerable to CVE-2026-12941, based on global website indexing conducted by WebTechSurvey.
The Dc Woocommerce Multi Vendor is affected by the CVE-2026-12941 vulnerability.
Dc Woocommerce Multi Vendor versions up to and including 5.0.9 are vulnerable to CVE-2026-12941.