The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site. This vulnerability allows users with the vendor role to escalate their privileges, potentially leading to site takeover. Defenders should assess exposure and prioritize remediati [truncated]
CVE-2026-81792 is a medium-severity vulnerability in the Product Catalog Enquiry for WooCommerce by MultiVendorX plugin, affecting versions up to 6.1.4. The vulnerability allows unauthenticated privilege escalation.
The MultiVendorX WordPress plugin before 5.0.15 has a vulnerability allowing unauthenticated users to retrieve sensitive information via a REST API listing route. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability exists due to a lack of proper authorization controls on one of its REST API listing routes, which allows access to vendor contact and payout details, pen [truncated]
The MultiVendorX WordPress plugin before 5.0.11 has a REST API endpoint vulnerability. This allows vendor-level users unauthorized access to financial data of other vendors due to inadequate authorization checks. The issue arises from the plugin's failure to verify that the requested store belongs to the current user. Consequently, any vendor-level user can potentially read other vendors' commission and f [truncated]