CVE-2026-16605: MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16605?
The severity of CVE-2026-16605 is rated at 68, indicating a moderate risk.
How do I fix CVE-2026-16605?
To fix CVE-2026-16605, update the MultiVendorX WordPress plugin to version 5.0.11 or later.
What types of stores are affected by CVE-2026-16605?
CVE-2026-16605 affects all stores managed by the MultiVendorX WordPress plugin prior to version 5.0.11.
What actions can an attacker perform due to CVE-2026-16605?
An attacker can view, take over, permanently delete, or modify any other vendor's store using the vulnerability.
Who is vulnerable to CVE-2026-16605?
Authenticated vendors with Store Owner permissions and above are vulnerable to CVE-2026-16605.