ZeroHour

CVE-2026-74925

moderate

Vendor-to-Admin Privilege Escalation in MultiVendorX WordPress Plugin (before 5.0.16)

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

The MultiVendorX WordPress plugin prior to 5.0.16 does not restrict which users can modify the plugin's role and capability settings, an improper privilege management flaw (CWE-269). A user holding the plugin's vendor role can reach those unprotected settings and grant the vendor role administrator-level capabilities. The next time that vendor acts with their role, they effectively hold administrator rights and can take over the site, including full read/write control and content or configuration changes. Any WordPress site running a MultiVendorX version before 5.0.16 is affected, especially multi-vendor marketplaces where several untrusted parties hold vendor accounts. There is no public proof-of-concept, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation is known.

What to do: Update MultiVendorX to version 5.0.16 or later. If immediate upgrade is not possible, restrict and review who holds the vendor role and audit vendor accounts and role definitions for unexpectedly granted administrator-level capabilities, checking for any unauthorized admin users or capability changes.

Affected
MultiVendorX (WordPress plugin)All versions before 5.0.16
Estimated exposure
moderateTens of thousands of sites (plugin reports roughly 30,000 active installs on WordPress.org) — Estimate based on the MultiVendorX plugin's WordPress.org listing of approximately 30,000 active installations, with exploitation further limited to sites where at least one untrusted vendor account exists.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

Ecosystems
WordPress
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.