CVE-2026-74925
moderateVendor-to-Admin Privilege Escalation in MultiVendorX WordPress Plugin (before 5.0.16)
The MultiVendorX WordPress plugin prior to 5.0.16 does not restrict which users can modify the plugin's role and capability settings, an improper privilege management flaw (CWE-269). A user holding the plugin's vendor role can reach those unprotected settings and grant the vendor role administrator-level capabilities. The next time that vendor acts with their role, they effectively hold administrator rights and can take over the site, including full read/write control and content or configuration changes. Any WordPress site running a MultiVendorX version before 5.0.16 is affected, especially multi-vendor marketplaces where several untrusted parties hold vendor accounts. There is no public proof-of-concept, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation is known.
What to do: Update MultiVendorX to version 5.0.16 or later. If immediate upgrade is not possible, restrict and review who holds the vendor role and audit vendor accounts and role definitions for unexpectedly granted administrator-level capabilities, checking for any unauthorized admin users or capability changes.
| MultiVendorX (WordPress plugin) | All versions before 5.0.16 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.