PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108695 multivendorx CVE debrief

CVE-2026-108695 MultiVendorX through 5.0.19 contains an incorrect authorization vulnerability via the settings REST endpoint, allowing vendor accounts to modify marketplace-wide settings. Defenders should assess exposure and verify setting integrity to prevent unauthorized changes. This vulnerability has a high severity with a CVSS score of 7.1 and affects WordPress installations with the MultiVendorX plugin. The vulnerability is gated only by edit_stores, allowing attackers with the store_owner role to send POST requests to /wp-json/multivendorx/v1/settings.

Vendor
multivendorx
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for WordPress installations with the MultiVendorX plugin should assess exposure and verify the integrity of marketplace-wide settings to prevent potential unauthorized changes. This includes verifying plugin version and configuration, restricting access to the settings REST endpoint, and monitoring for suspicious activity related to the MultiVendorX plugin. Security teams and operators should prioritize verifying exposure and taking

Why it matters

CVE-2026-108695 is a high-severity vulnerability in the MultiVendorX WordPress plugin that allows unauthorized modifications to marketplace-wide settings. Defenders should prioritize verifying exposure and assessing the integrity of settings to prevent potential unauthorized changes.

  • Defenders must verify exposure of MultiVendorX installations to unauthorized setting modifications
  • Compromise of marketplace-wide settings could lead to unauthorized changes in commission, payout, and onboarding settings
  • Defenders should restrict access to the settings REST endpoint to prevent unauthorized modifications
  • Verification of plugin version and configuration is necessary to ensure integrity of marketplace-wide settings

Technical summary

The MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. Attackers with the store_owner role can send POST requests to /wp-json/multivendorx/v1/settings, gated only by edit_stores, to overwrite commission, payout, and onboarding settings. This vulnerability has a high severity with a CVSS score of 7.1 and affects WordPress installations with the MultiVendorX plugin. Defenders should prioritize verifying exposure and assessing the integrity of marketplace-wide settings.

Defensive priority

Defenders should prioritize verifying exposure of MultiVendorX installations and assessing the integrity of marketplace-wide settings.

Recommended defensive actions

  • Verify MultiVendorX installations for exposure to the incorrect authorization vulnerability
  • Assess the integrity of marketplace-wide settings
  • Restrict access to the settings REST endpoint
  • Monitor for suspicious activity related to the MultiVendorX plugin
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the incorrect authorization vulnerability in MultiVendorX through 5.0.19. The vulnerability allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. The source item and CVE record provide evidence of the vulnerability but have limited detail on affected scope and severity. Defenders should verify exposure and assess setting integrity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108695 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108695

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108695 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108695

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • MultiVendorX through 5.0.19 Incorrect Authorization via Settings REST Endpoint

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108695.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/multivendorx/multivendorx/issues/2375

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/multivendorx/multivendorx

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://github.com/multivendorx/multivendorx/blob/8a717799b02f698e4b2b61a282062a41fbe15183/plugins/multivendorx/classes/RestAPI/Controllers/Settings.php

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://wordpress.org/plugins/dc-woocommerce-multi-vendor/

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/multivendorx-through-5.0.19-incorrect-authorization-via-settings-rest-endpoint

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.