Impact
The vulnerability is an unauthenticated broken access control flaw that allows attackers to access or modify resources that should be restricted. Because the flaw does not require prior authentication, an attacker could retrieve sensitive vendor or order information, potentially leading to data disclosure or further exploitation of the site. The weakness is identified as an improper authorization issue, which can undermine the overall security posture of a multi‑vendor WordPress site.
Affected Systems
The flaw affects the MultiVendorX plugin for WordPress, versions 5.0.14 and earlier. Users running any of these versions are at risk until they upgrade to a fixed release.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is moderate and could be exploited by unauthenticated users who submit crafted requests to the plugin’s endpoints. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a direct HTTP request to the plugin’s protected functions, which does not require authentication. While no public exploit is indicated, the nature of the flaw means that a determined attacker could leverage it to gain unauthorized access or modify data.
OpenCVE Enrichment