CVE-2026-74925 PUBLISHED

MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator

Assigner: WPScan
Reserved: 17.08.2026 Published: 11.09.2026 Updated: 11.09.2026

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

Product Status

Vendor Unknown
Product MultiVendorX
Versions Default: unaffected
  • affected from 5.0.0 to 5.0.16 (excl.)

Credits

  • Philipp Doblhofer finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE