PatchSiren cyber security CVE debrief
CVE-2026-108695 multivendorx CVE debrief
CVE-2026-108695 MultiVendorX through 5.0.19 contains an incorrect authorization vulnerability via the settings REST endpoint, allowing vendor accounts to modify marketplace-wide settings. Defenders should assess exposure and verify setting integrity to prevent unauthorized changes. This vulnerability has a high severity with a CVSS score of 7.1 and affects WordPress installations with the MultiVendorX plugin. The vulnerability is gated only by edit_stores, allowing attackers with the store_owner role to send POST requests to /wp-json/multivendorx/v1/settings.
- Vendor
- multivendorx
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for WordPress installations with the MultiVendorX plugin should assess exposure and verify the integrity of marketplace-wide settings to prevent potential unauthorized changes. This includes verifying plugin version and configuration, restricting access to the settings REST endpoint, and monitoring for suspicious activity related to the MultiVendorX plugin. Security teams and operators should prioritize verifying exposure and taking
Why it matters
CVE-2026-108695 is a high-severity vulnerability in the MultiVendorX WordPress plugin that allows unauthorized modifications to marketplace-wide settings. Defenders should prioritize verifying exposure and assessing the integrity of settings to prevent potential unauthorized changes.
- Defenders must verify exposure of MultiVendorX installations to unauthorized setting modifications
- Compromise of marketplace-wide settings could lead to unauthorized changes in commission, payout, and onboarding settings
- Defenders should restrict access to the settings REST endpoint to prevent unauthorized modifications
- Verification of plugin version and configuration is necessary to ensure integrity of marketplace-wide settings
Technical summary
The MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. Attackers with the store_owner role can send POST requests to /wp-json/multivendorx/v1/settings, gated only by edit_stores, to overwrite commission, payout, and onboarding settings. This vulnerability has a high severity with a CVSS score of 7.1 and affects WordPress installations with the MultiVendorX plugin. Defenders should prioritize verifying exposure and assessing the integrity of marketplace-wide settings.
Defensive priority
Defenders should prioritize verifying exposure of MultiVendorX installations and assessing the integrity of marketplace-wide settings.
Recommended defensive actions
- Verify MultiVendorX installations for exposure to the incorrect authorization vulnerability
- Assess the integrity of marketplace-wide settings
- Restrict access to the settings REST endpoint
- Monitor for suspicious activity related to the MultiVendorX plugin
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the incorrect authorization vulnerability in MultiVendorX through 5.0.19. The vulnerability allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. The source item and CVE record provide evidence of the vulnerability but have limited detail on affected scope and severity. Defenders should verify exposure and assess setting integrity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108695 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108695
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108695 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108695
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MultiVendorX through 5.0.19 Incorrect Authorization via Settings REST Endpoint
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108695.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/multivendorx/multivendorx/issues/2375
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/multivendorx/multivendorx
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://github.com/multivendorx/multivendorx/blob/8a717799b02f698e4b2b61a282062a41fbe15183/plugins/multivendorx/classes/RestAPI/Controllers/Settings.php
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://wordpress.org/plugins/dc-woocommerce-multi-vendor/
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/multivendorx-through-5.0.19-incorrect-authorization-via-settings-rest-endpoint
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.