Ghostwire

CVE-2026-16746: The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in...

MEDIUM CVSS 0.0

Published: August 5, 2026 | Last Modified: August 5, 2026

Description

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References