Impact
The vulnerability is an unauthenticated broken access control flaw in the MultiVendorX plugin for WordPress. Because the plugin does not properly enforce permission checks, an attacker could perform actions normally reserved for administrators, such as managing products, viewing sensitive data, or modifying site settings. The flaw is categorized as CWE‑862, which highlights a lack of proper authorization.
Affected Systems
Affected systems are sites running the WordPress MultiVendorX plugin version 5.0.10 or earlier. The plugin is commonly used in e‑commerce WordPress installations to enable multi‑vendor marketplaces. No other product or version ranges are listed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. Attack likely occurs via unauthenticated access to the vendor area or REST endpoint provided by the plugin; an adversary could craft a request that bypasses role checks and gains elevated privileges. Given the lack of authentication requirement, the threat exposure is significant for any publicly accessible WordPress site that has the vulnerable plugin installed.
OpenCVE Enrichment