Impact
The vulnerability allows any user assigned the MultiVendorX vendor role to modify role capabilities. Because updates to administrative capabilities are not access‑controlled, a vendor can grant themselves administrator privileges, thereby bypassing normal authorization checks. This direct privilege escalation could lead to complete takeover of the WordPress site, compromising confidentiality, integrity, and availability.
Affected Systems
The affected product is the MultiVendorX WordPress plugin version 5.0.0 through 5.0.15. The flaw exists in the role and capability management code that runs when the plugin is enabled on any WordPress installation. Sites using these versions have no restriction on who can alter role settings, making all users with the vendor role susceptible.
Risk and Exploitability
Although no EPSS score is available, the flaw is severe because any vendor role user can obtain administrator privileges without external interaction. The CVSS score is not provided, but the lack of access control represents a high severity risk. The vulnerability is present in every instance of the affected plugin, so widespread exploitation is possible if the plugin remains unpatched. The vulnerability is not currently listed in the CISA KEV catalog, but the potential for site takeover warrants immediate remediation.
OpenCVE Enrichment