PatchSiren

MultiVendorX CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH MultiVendorX CVE published 2026-09-11

CVE-2026-74925

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site. This vulnerability allows users with the vendor role to escalate their privileges, potentially leading to site takeover. Defenders should assess exposure and prioritize remediati [truncated]

MEDIUM MultiVendorX CVE published 2026-09-08

CVE-2026-81792

CVE-2026-81792 is a medium-severity vulnerability in the Product Catalog Enquiry for WooCommerce by MultiVendorX plugin, affecting versions up to 6.1.4. The vulnerability allows unauthenticated privilege escalation.

MEDIUM MultiVendorX CVE published 2026-09-02

CVE-2026-74927

The MultiVendorX WordPress plugin before 5.0.15 has a vulnerability allowing unauthenticated users to retrieve sensitive information via a REST API listing route. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability exists due to a lack of proper authorization controls on one of its REST API listing routes, which allows access to vendor contact and payout details, pen [truncated]

LOW MultiVendorX CVE published 2026-08-05

CVE-2026-16746

The MultiVendorX WordPress plugin before 5.0.11 has a REST API endpoint vulnerability. This allows vendor-level users unauthorized access to financial data of other vendors due to inadequate authorization checks. The issue arises from the plugin's failure to verify that the requested store belongs to the current user. Consequently, any vendor-level user can potentially read other vendors' commission and f [truncated]