The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-05 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-16605
Mitre link : CVE-2026-16605
CVE.ORG link : CVE-2026-16605
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
