CVE-2026-108695
Received Received - Intake

Incorrect Authorization in MultiVendorX WordPress Plugin Allows Privilege Escalation

Vulnerability report for CVE-2026-108695, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. Attackers with the store_owner role can send POST requests to /wp-json/multivendorx/v1/settings, gated only by edit_stores, to overwrite commission, payout, and onboarding settings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
multivendorx MultiVendorX 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an incorrect authorization flaw in the MultiVendorX WordPress plugin (versions up to 5.0.19). It allows vendor accounts with the store_owner role to modify marketplace-wide settings via a REST endpoint. Attackers can send POST requests to /wp-json/multivendorx/v1/settings and overwrite critical settings like commission, payout, and onboarding configurations. The issue stems from improper permission checks that rely on the edit_stores capability instead of requiring administrative privileges.

Detection Guidance

Check WordPress sites using MultiVendorX plugin versions up to 5.0.19. Inspect server logs for POST requests to /wp-json/multivendorx/v1/settings from non-admin users. Use commands like grep -r 'multivendorx/v1/settings' /var/log/nginx/ or similar for web server logs.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to alter marketplace settings, potentially disrupting vendor payouts, changing commission structures, or modifying onboarding processes. Attackers with store_owner roles could gain unauthorized administrative control over the marketplace, affecting all vendors and customers. The impact includes financial losses, operational disruptions, and compromised trust in the platform.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to sensitive data. GDPR requires strict access controls for personal data, while HIPAA mandates secure handling of health-related information. Unauthorized modifications to marketplace settings could expose user data or violate privacy regulations, resulting in legal penalties and reputational damage.

Mitigation Strategies

Update MultiVendorX plugin to the latest version beyond 5.0.19. Temporarily restrict access to the /wp-json/multivendorx/v1/settings endpoint via .htaccess or web server rules. Review and remove edit_stores capability from store_owner role in plugin settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108695. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart