← WordPress Vulnerabilities
WordPress security by component

multivendorx

multivendorx transforms WooCommerce stores into multivendor marketplaces with vendor management and marketplace functionality.

multivendorx (multivendorx) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 7.5.

Plugin slug: multivendorx

CVE-2026-16746: MultiVendorX vendor REST access exposes competing-store financial data

MultiVendorX before 5.0.11 has a REST API endpoint that does not verify that the requested store belongs to the authenticated vendor. A vendor-level user can supply another store's identifier and retrieve that vendor's commission and financial information. This unscored record received deeper review because it provides a low-privilege cross-tenant financial-data disclosure primitive. The CNA does not disclose the route, HTTP method or identifier parameter.

PublishedAug 05, 2026
Known safe version5.0.11
Published vulnerabilities for multivendorx
Safe version
Aug 05, 2026 CVE-2026-16746
MultiVendorX vendor REST access exposes competing-store financial data
MultiVendorX before 5.0.11 has a REST API endpoint that does not verify that the requested store belongs to the authenticated vendor. A vendor-level user can supply another store's identifier and retrieve that vendor's commission and financial information. This unscored record received deeper review because it provides a low-privilege cross-tenant financial-data disclosure primitive. The CNA does not disclose the route, HTTP method or identifier parameter.
5.0.11
CVE2.7
NVDPending
Aug 05, 2026 CVE-2026-16605
MultiVendorX store-owner REST access permits competing-store takeover
MultiVendorX before 5.0.11 exposes REST operations that do not verify that the targeted store belongs to the authenticated Store Owner. A vendor can supply another store's identifier and view, modify, take over or permanently delete that store. This unscored record received deeper review because a low-privilege cross-tenant authorization bypass permits destructive changes and privilege over another vendor's assets. The CNA does not disclose the routes, HTTP methods or identifier parameter.
5.0.11
CVE7.2
NVDPending
Jun 09, 2025 CVE-2025-48261
MultiVendorX: A security weakness
MultiVendorX is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.5
NVDPending
May 19, 2025 CVE-2025-48263
MultiVendorX: Cross-site scripting
MultiVendorX is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVD5.4