CVE-2026-12951 Overview
CVE-2026-12951 is a SQL Injection vulnerability in the Dc WooCommerce Multi Vendor plugin for WordPress. The flaw affects all versions up to and including 5.0.18 and resides in the /multivendorx/v1/compliance/report-abuse REST endpoint. The order_by parameter is concatenated into an ORDER BY clause after being passed through esc_sql(), which does not neutralize injection in that context. Authenticated users with vendor-level access or higher (the edit_stores capability) can append arbitrary SQL to extract data from the backing database. The weakness is classified as [CWE-89] Improper Neutralization of Special Elements used in an SQL Command.
Critical Impact
Authenticated vendors can exfiltrate sensitive data from the WordPress database, including user records and session artifacts, through a crafted order_by value.
Affected Products
- Dc WooCommerce Multi Vendor plugin for WordPress — versions up to and including 5.0.18
- WordPress sites exposing the /multivendorx/v1/compliance/report-abuse REST route
- Multi-vendor marketplaces granting the edit_stores capability to vendor accounts
Discovery Timeline
- 2026-10-02 - CVE-2026-12951 published to NVD
- 2026-10-03 - Last updated in NVD database
Technical Details for CVE-2026-12951
Vulnerability Analysis
The vulnerability resides in the MarketplaceCompliance module of the Dc WooCommerce Multi Vendor plugin. The REST handler defined in Rest.php accepts an order_by parameter from the request and forwards it to a database helper in Util.php. The helper constructs an ORDER BY clause by concatenating the attacker-controlled value directly into the SQL string. Only esc_sql() is applied to the input before concatenation.
esc_sql() escapes characters required to break out of quoted string literals, such as single quotes and backslashes. It provides no sanitization for identifiers or clause fragments used outside of quoted strings. Because ORDER BY arguments are not quoted, an attacker can supply SQL expressions, subqueries, or UNION-style constructs without needing to escape a string delimiter.
Root Cause
The root cause is improper input handling for a SQL identifier context. The plugin treats esc_sql() as a general-purpose sanitizer, but WordPress documentation explicitly limits it to string-literal escaping. Secure handling requires validating order_by against an allowlist of known column names or using $wpdb->prepare() with a controlled identifier set.
Attack Vector
Exploitation requires an authenticated session with the edit_stores capability, typically granted to marketplace vendors. The attacker sends a request to the /multivendorx/v1/compliance/report-abuse REST endpoint with a crafted order_by value containing a SQL fragment. The injected payload appends a subquery or conditional expression that forces the database to return attacker-chosen data through time-based, boolean-based, or stacked query techniques, depending on the backend configuration. The attack is network-reachable and does not require user interaction.
See the WordPress Plugin Code Snippet and WordPress Plugin Utility Code for the vulnerable call paths. No verified public exploit code has been published.
Detection Methods for CVE-2026-12951
Indicators of Compromise
- Requests to /wp-json/multivendorx/v1/compliance/report-abuse containing SQL keywords such as SELECT, UNION, SLEEP, BENCHMARK, or IF( inside the order_by parameter.
- Unexpected ORDER BY clauses in MySQL general query logs tied to the WordPress service account.
- Vendor accounts issuing high-volume or time-delayed REST calls to the compliance endpoint.
Detection Strategies
- Enable WordPress REST API request logging and alert on non-alphanumeric characters in the order_by parameter of the report-abuse route.
- Enable MySQL slow query and general query logs to capture injected ORDER BY fragments and time-based payloads.
- Deploy web application firewall rules that block SQL metacharacters in query-string parameters targeting the multivendorx/v1/compliance/* namespace.
Monitoring Recommendations
- Audit all accounts holding the edit_stores capability and track their REST endpoint usage.
- Monitor database error rates and anomalous SELECT volumes from the WordPress database user.
- Alert on repeated 500-series responses from /multivendorx/v1/compliance/report-abuse, which often indicate failed injection attempts.
How to Mitigate CVE-2026-12951
Immediate Actions Required
- Upgrade the Dc WooCommerce Multi Vendor plugin to a release later than 5.0.18 that includes the published fix.
- Restrict or revoke the edit_stores capability from untrusted vendor accounts until patching is complete.
- Review database audit logs for unexpected SELECT, UNION, or time-based queries originating from the WordPress service account.
Patch Information
The vendor committed a fix tracked in the plugin repository. See the WordPress Plugin Changeset and the Wordfence Vulnerability Report for the authoritative advisory and patched version details. Apply the vendor update through the WordPress plugin management console or by replacing the plugin files directly.
Workarounds
- Block external access to the /wp-json/multivendorx/v1/compliance/report-abuse route at the web server or WAF layer until the plugin is updated.
- Add a WAF rule that rejects requests where order_by contains characters outside [A-Za-z0-9_].
- Temporarily disable the MarketplaceCompliance module if the deployment does not rely on abuse reporting workflows.
# Example nginx rule to block suspicious order_by values
location ~ ^/wp-json/multivendorx/v1/compliance/report-abuse {
if ($arg_order_by ~* "[^A-Za-z0-9_]") {
return 403;
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.