CVE-2026-74925
MultiVendorX · MultiVendorX WordPress Plugin
The MultiVendorX WordPress plugin fails to validate user permissions, allowing users with the vendor role to escalate their privileges to administrator and gain full control over the affected site.
Executive summary
The MultiVendorX WordPress plugin contains a critical privilege management flaw that allows authenticated vendor users to perform a full administrative site takeover.
Vulnerability
This is an improper privilege management vulnerability (CWE-269) where the plugin fails to perform necessary capability checks, allowing an authenticated user with the vendor role to modify security settings and grant themselves administrator privileges.
Business impact
A successful exploit results in a complete compromise of the WordPress installation, enabling the attacker to modify site content, exfiltrate sensitive customer data, or install malicious backdoors. With a CVSS score of 7.2, the vulnerability is classified as high severity, posing a significant risk to site integrity and organizational data security.
Remediation
Immediate Action: Update the MultiVendorX plugin to version 5.0.16 or later immediately to resolve the privilege management flaw.
Proactive Monitoring: Review WordPress user account activity logs for unauthorized role changes or the creation of new administrator accounts by existing vendors.
Compensating Controls: Limit access to the vendor dashboard for untrusted users and ensure that administrative privileges are strictly audited until the patch can be deployed.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for total site takeover, organizations using the MultiVendorX plugin must prioritize this update. Administrators should verify that no unauthorized administrative accounts were created by vendors prior to the application of the security patch.
More MultiVendorX CVEs
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.2 (3.1)
- Analyst report written
Sources
Originally found and disclosed by Philipp Doblhofer, with WPScan (coordinator), per the CVE Program record.