← WordPress Vulnerabilities
WordPress security by component

multivendorx

multivendorx transforms WooCommerce stores into multivendor marketplaces with vendor management and marketplace functionality.

multivendorx (multivendorx) is a WordPress plugin with 5 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 7.5.

Plugin slug: multivendorx

CVE-2026-74925: MultiVendorX vendors can grant themselves administrator powers

MultiVendorX before 5.0.16 does not restrict updates to its role and capability settings. A user holding the plugin's Vendor role can assign administrator-level capabilities to that role and take over the site. The authoritative export does not identify the settings endpoint, action, or capability parameter.

PublishedSep 11, 2026
Known safe version5.0.16
Published vulnerabilities for multivendorx
Safe version
Sep 11, 2026 CVE-2026-74925
MultiVendorX vendors can grant themselves administrator powers
MultiVendorX before 5.0.16 does not restrict updates to its role and capability settings. A user holding the plugin's Vendor role can assign administrator-level capabilities to that role and take over the site. The authoritative export does not identify the settings endpoint, action, or capability parameter.
5.0.16
CVE7.2
NVDPending
Aug 05, 2026 CVE-2026-16746
MultiVendorX vendor REST access exposes competing-store financial data
MultiVendorX before 5.0.11 has a REST API endpoint that does not verify that the requested store belongs to the authenticated vendor. A vendor-level user can supply another store's identifier and retrieve that vendor's commission and financial information. This unscored record received deeper review because it provides a low-privilege cross-tenant financial-data disclosure primitive.
5.0.11
CVE2.7
NVDPending
Aug 05, 2026 CVE-2026-16605
MultiVendorX store-owner REST access permits competing-store takeover
MultiVendorX before 5.0.11 exposes REST operations that do not verify that the targeted store belongs to the authenticated Store Owner. A vendor can supply another store's identifier and view, modify, take over or permanently delete that store. This unscored record received deeper review because a low-privilege cross-tenant authorization bypass permits destructive changes and privilege over another vendor's assets.
5.0.11
CVE7.2
NVDPending
Jun 09, 2025 CVE-2025-48261
MultiVendorX: A security weakness
MultiVendorX is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
May 19, 2025 CVE-2025-48263
MultiVendorX: Cross-site scripting
MultiVendorX is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4