Impact
The MultiVendorX WordPress plugin allows an authenticated vendor to access its REST API without verifying that the target store belongs to the requesting vendor. This missing authorization step lets the vendor view, take over, modify, or permanently delete any other vendor's store in the marketplace, giving that vendor unauthorized control over another store's data. The bug falls under improper access control, allowing a vendor to perform actions reserved for the store owner or administrators.
Affected Systems
WordPress installations that use the MultiVendorX plugin version prior to 5.0.11 are affected. Any user with vendor or higher role who is authenticated can exploit this issue.
Risk and Exploitability
Because the flaw requires only an authenticated vendor account and can be exploited through the plugin's publicly documented REST API, the risk of privilege escalation is high. The CVSS score is not reported, but the absence of an EPSS score indicates no publicly known exploitation frequency yet; however, the vulnerability is not listed in CISA KEV, suggesting it has not yet been observed in the wild. Regardless, the impact on data integrity and availability is significant, and the attack can be performed remotely through normal API traffic by mounting a credentialed attack.
OpenCVE Enrichment