CVE-2026-74927

The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 06:17

Updated : 2026-09-03 17:50


NVD link : CVE-2026-74927

Mitre link : CVE-2026-74927

CVE.ORG link : CVE-2026-74927


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization