CVE-2026-74925
Received
Received - Intake
Unauthorized Privilege Escalation in MultiVendorX WordPress Plugin
Vulnerability report for CVE-2026-74925, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-11
Last updated on: 2026-09-11
Assigner: WPScan
Description
Description
The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| multivendorx | wordpress_plugin | to 5.0.16 (exc) |
| multivendorx | plugin | From 5.0.0 (inc) to 5.0.16 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |