Unknown MultiVendorX

3 known vulnerabilities in Unknown MultiVendorX, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-74926 CVSS 7.1 high The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API…
  • CVE-2026-74925 CVSS 7.2 high The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding…
  • CVE-2026-74927 CVSS 5.3 medium The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes…