CVE-2026-74926
MultiVendorX 5.0.0 - 5.0.15 - Subscriber+ Arbitrary Store Data and Ownership Overwrite via stores REST Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API routes, allowing any authenticated user, such as a subscriber, to overwrite any store's details and payout settings and to replace the record of who owns it.
| Vendor | unknown |
| Product | multivendorx |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown multivendorx
Be the first to know when new unknown vulnerabilities affecting unknown multivendorx are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / MultiVendorX
5.0.0 < 5.0.16
References
Credits
Farid Narimanov WPScan