Impact
The MultiVendorX WordPress plugin fails to verify store ownership in an exposed REST API route. Any authenticated user, including those with Subscriber role, can submit requests to modify any store’s configuration and payout details, and can even overwrite the store's owner record. This allows attackers to take control of stores they do not own, potentially enabling fraudulent transactions and financial loss.
Affected Systems
All installations of the MultiVendorX WordPress plugin running versions 5.0.0 through 5.0.15 are impacted. The vulnerability affects the plugin's REST API endpoints that manage store data. WordPress sites that deploy these plugin versions are at risk.
Risk and Exploitability
The EPSS score is below 1%, indicating a low likelihood of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, because the flaw can be exploited by any authenticated user, the risk profile is moderate to high. An attacker only needs a valid WordPress account; exploiting the REST endpoint does not require privilege escalation beyond the existing role. Once accessed, the attacker can overwrite arbitrary store information and change ownership, leading to potential financial damage.
OpenCVE Enrichment