Description
The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.
Published: 2026-09-11
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The MultiVendorX WordPress plugin allows users assigned the vendor role to update role and capability settings without any restriction on access control. Because this setting update is not authorized, a vendor can reassign administrator‑level capabilities to themselves, enabling complete takeover of the site. This flaw directly compromises confidentiality, integrity, and availability of the WordPress installation by allowing a privileged escalation from vendor to administrator level.

Affected Systems

The affected product is the MultiVendorX WordPress plugin versions 5.0.0 through 5.0.15. The role and capability management code runs whenever the plugin is enabled on any WordPress installation. Sites using these versions have no restriction on who can alter role settings.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity; however, the EPSS score of less than 1% suggests a low probability of exploitation in the wild. Because any user with the vendor role can grant administrator rights without external interaction, the vulnerability could be exploited if the plugin is left unpatched. This risk is not amplified by being listed in the CISA KEV catalog, and remediation focuses on applying the latest patch.

Generated by OpenCVE AI on September 11, 2026 at 16:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MultiVendorX plugin to version 5.0.16 or and capability updates.
  • Immediately remove any administrator privileges from accounts to their original permissions.
  • Restrict the vendor role’s ability to modify role capabilities by disabling that feature in the plugin settings or using custom code to enforce access control.
  • Verify that no unauthorized administrator accounts exist and delete or re‑assign them before re‑enabling the plugin.

Generated by OpenCVE AI on September 11, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Multivendorx
Multivendorx multivendorx
Wordpress
Wordpress wordpress
Vendors & Products Multivendorx
Multivendorx multivendorx
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.
Title MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator
References

Subscriptions

Multivendorx Multivendorx
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T10:09:48.714Z

Reserved: 2026-08-17T11:31:48.486Z

Link: CVE-2026-74925

cve-icon Vulnrichment

Updated: 2026-09-11T10:02:18.713Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:46.740

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-74925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:08Z

Weaknesses
  • CWE-269

    Improper Privilege Management