Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108695

HIGH NVD
CVSS Score 7.1
Severity HIGH
Published Oct 11, 2026
Vendor unknown

Description

MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. Attackers with the store_owner role can send POST requests to /wp-json/multivendorx/v1/settings, gated only by edit_stores, to overwrite commission, payout, and onboarding settings.

References