Impact
The MultiVendorX WordPress plugin allows users assigned the vendor role to update role and capability settings without any restriction on access control. Because this setting update is not authorized, a vendor can reassign administrator‑level capabilities to themselves, enabling complete takeover of the site. This flaw directly compromises confidentiality, integrity, and availability of the WordPress installation by allowing a privileged escalation from vendor to administrator level.
Affected Systems
The affected product is the MultiVendorX WordPress plugin versions 5.0.0 through 5.0.15. The role and capability management code runs whenever the plugin is enabled on any WordPress installation. Sites using these versions have no restriction on who can alter role settings.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity; however, the EPSS score of less than 1% suggests a low probability of exploitation in the wild. Because any user with the vendor role can grant administrator rights without external interaction, the vulnerability could be exploited if the plugin is left unpatched. This risk is not amplified by being listed in the CISA KEV catalog, and remediation focuses on applying the latest patch.
OpenCVE Enrichment