CVE-2026-108695
HIGH
NVD
CVSS Score
7.1
Severity
HIGH
Published
Oct 11, 2026
Vendor
unknown
Description
MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. Attackers with the store_owner role can send POST requests to /wp-json/multivendorx/v1/settings, gated only by edit_stores, to overwrite commission, payout, and onboarding settings.
References
- https://github.com/multivendorx/multivendorx
- https://github.com/multivendorx/multivendorx/blob/8a717799b02f698e4b2b61a282062a41fbe15183/plugins/multivendorx/classes/RestAPI/Controllers/Settings.php#L157-L172
- https://github.com/multivendorx/multivendorx/blob/8a717799b02f698e4b2b61a282062a41fbe15183/plugins/multivendorx/classes/RestAPI/Controllers/Settings.php#L77-L80
- https://github.com/multivendorx/multivendorx/issues/2375
- https://wordpress.org/plugins/dc-woocommerce-multi-vendor/