PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74927 MultiVendorX CVE debrief

The MultiVendorX WordPress plugin before 5.0.15 has a vulnerability allowing unauthenticated users to retrieve sensitive information via a REST API listing route. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability exists due to a lack of proper authorization controls on one of its REST API listing routes, which allows access to vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications. Users of the plugin should be aware of this vulnerability and take steps to mitigate it by applying patches or updates to version 5.0.15 or later.

Vendor
MultiVendorX
Product
MultiVendorX WordPress plugin
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Users of the MultiVendorX WordPress plugin, particularly those with versions before 5.0.15, should be aware of this vulnerability and take steps to mitigate it. This includes applying patches or updates to version 5.0.15 or later, restricting access to the affected REST API listing route, and monitoring for suspicious activity related to the MultiVendorX plugin. Additionally, users should review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Operators, platform administrators, vulnerability management teams, and security teams should all be aware of the potential impact and take appropriate action to protect their systems and data. This vulnerability could potentially allow unauthorized access to sensitive information, which could lead to further exploitation or compromise of affected systems. Therefore, it is essential to prioritize patching and mitigation efforts to minimize the risk of exploitation. Furthermore, users should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up to ensure timely remediation and minimize potential damage. By taking these steps, users can help protect their systems and data from potential exploitation of this vulnerability. The vulnerability's MEDIUM severity and CVSS score of 5.3 highlight the importance of prompt action to mitigate its impact. Overall, a proactive and thorough approach to addressing this vulnerability is crucial to maintaining the security and integrity of affected systems and data. Users should also consider the potential operational impact of this vulnerability and review the context of their specific environment to ensure that they are adequately prepared to address it. By doing so, they can help prevent potential security breaches and maintain the trust and confidence of their users and stakeholders. In addition to patching and mitigation, users should also prioritize monitoring and detection to quickly identify and respond to potential exploitation attempts. This includes reviewing relevant monitoring, detection

Technical summary

The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorization controls on one of its REST API listing routes. This allows unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Affected users should apply patches or updates to the MultiVendorX WordPress plugin to version 5.0.15 or later to mitigate this vulnerability. Restricting access to the affected REST API listing route and monitoring for suspicious activity related to the MultiVendorX plugin are also recommended.

Defensive priority

Apply patches or updates to the MultiVendorX WordPress plugin to version 5.0.15 or later to mitigate this vulnerability.

Recommended defensive actions

  • Apply patches or updates to the MultiVendorX WordPress plugin to version 5.0.15 or later.
  • Restrict access to the affected REST API listing route.
  • Monitor for suspicious activity related to the MultiVendorX plugin.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Review the context of your specific environment to ensure that you are adequately prepared to address this vulnerability.

Evidence notes

The vulnerability exists in the MultiVendorX WordPress plugin before version 5.0.15. The plugin lacks proper authorization controls on one of its REST API listing routes, allowing unauthenticated users to access sensitive information including vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74927 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74927

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74927 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74927

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.