Impact
The MultiVendorX WordPress plugin fails to enforce authorization on a REST API route that returns store information, meaning any user can trigger the endpoint and obtain vendor personal data, payout amounts, and administrative notes. This direct leakage of identity and sensitive personal information, as well as financial figures, represents an unauthorized disclosure of vendor PII and payout data. The flaw allows unrestricted access to confidential data, constituting a clear confidentiality breach.
Affected Systems
WordPress installations that have installed the MultiVendorX plugin version 5.0.13 up to 5.0.14 are affected. Any host running the plugin before the 5.0.15 release retains the vulnerable stores endpoint regardless of site configuration or other security plugins.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is less than 1%, showing a low but non-zero likelihood of exploitation. Because the vulnerability exists for unauthenticated clients, it is inferred that an attacker can simply issue a REST request to the exposed route to retrieve the sensitive data with no credentials. Although it is inferred that no exploit code has been published, the lack of access control means the exploit is trivial. The vulnerability is not listed in the CISA KEV catalog, but the potential for business reputational and financial impact remains.
OpenCVE Enrichment