HIGH

CVE-2026-16605

2026-08-05 CVSS v3.1
CVSS
7.2

Description

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.32%
Probability of exploitation in next 30 days
24.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE