← WordPress Vulnerabilities
WordPress security by component

MultiVendorX

MultiVendorX converts WooCommerce stores into multi-vendor marketplaces with vendor management, product listings, commissions, and order handling.

MultiVendorX (dc-woocommerce-multi-vendor) is a WordPress plugin with 20 published CVE records in this archive. The latest tracked vulnerability was published Sep 16, 2026; the highest published CVSS base score is 9.8.

Plugin slug: dc-woocommerce-multi-vendor

CVE-2026-74926: MultiVendorX lets subscribers overwrite another store's ownership and payouts

MultiVendorX from 5.0.0 up to but not including 5.0.16: Any authenticated user, including a Subscriber, can act on a selected store through a REST route that does not verify ownership. Attacker-controlled updates can replace store details, payout settings and the recorded owner. The export does not name the route, store selector or writable field names; theft of an actual payout is not independently established.

PublishedSep 16, 2026
Known safe version5.0.16
Published vulnerabilities for dc-woocommerce-multi-vendor
Safe version
Sep 16, 2026 CVE-2026-74926
MultiVendorX lets subscribers overwrite another store's ownership and payouts
MultiVendorX from 5.0.0 up to but not including 5.0.16: Any authenticated user, including a Subscriber, can act on a selected store through a REST route that does not verify ownership. Attacker-controlled updates can replace store details, payout settings and the recorded owner. The export does not name the route, store selector or writable field names; theft of an actual payout is not independently established.
5.0.16
CVE7.1
NVDPending
Sep 02, 2026 CVE-2026-74927
MultiVendorX exposes vendor payout and application data
MultiVendorX 5.0.13 and 5.0.14 does not authorize one REST API listing route. An unauthenticated visitor can retrieve vendor contact details, payout details, pending payout amounts, and administrative notes attached to store applications.
5.0.15
CVE5.3
NVDPending
Aug 18, 2026 CVE-2026-66651
MultiVendorX: Broken access control
MultiVendorX is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.0.14.
See mitigation notes
CVE6.5
NVDPending
Aug 13, 2026 CVE-2026-66441
MultiVendorX: Broken access control
MultiVendorX is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.0.10.
5.0.11
CVE7.5
NVDPending
Jul 16, 2026 CVE-2026-12941
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions: SQL injection
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.0.9.
See mitigation notes
CVE6.5
NVDPending
Oct 22, 2025 CVE-2025-49916
MultiVendorX: A security weakness
MultiVendorX is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.6
NVDPending
May 17, 2025 CVE-2025-4101
MultiVendorX – WooCommerce Multivendor Marketplace Solutions: A security weakness
MultiVendorX – WooCommerce Multivendor Marketplace Solutions is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Apr 05, 2025 CVE-2025-2789
Next Amazon, eBay, Etsy: A security weakness
Next Amazon, eBay, Etsy is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD6.5
Jan 31, 2025 CVE-2025-0493
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution: Filesystem traversal
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.8
NVD9.8
Jan 24, 2025 CVE-2025-24706
MultiVendorX: Cross-site scripting
MultiVendorX is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Dec 09, 2024 CVE-2023-51355
MultiVendorX: A security weakness
MultiVendorX is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.2
NVDPending
Oct 24, 2024 CVE-2024-9943
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution: Cross-site request forgery
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.3
NVDPending
Oct 24, 2024 CVE-2024-9531
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution: A security weakness
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Sep 04, 2024 CVE-2024-8289
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution: Privilege escalation or authentication bypass
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Aug 12, 2024 CVE-2024-43213
WC Marketplace: Cross-site scripting
WC Marketplace is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jun 11, 2024 CVE-2024-24703
WC Marketplace: A security weakness
WC Marketplace is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.6
NVDPending
Jun 09, 2024 CVE-2024-31304
WC Marketplace: A security weakness
WC Marketplace is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.1
NVD8.8
Jun 06, 2024 CVE-2024-5259
MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution: Cross-site scripting
MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 29, 2024 CVE-2024-30433
WC Marketplace: Cross-site scripting
WC Marketplace is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jul 01, 2023 CVE-2020-36741
MultiVendorX: Cross-site request forgery
MultiVendorX is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3