CVE-2026-74925: MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator
The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MultiVendorX WordPress pluginto a version that resolves this vulnerability.Fixed in 5.0.16 - Compensating control
Restrict who can update role and capability settings for the MultiVendorX WordPress plugin so that only trusted administrators can change those permissions (users holding the vendor role should not be allowed to grant administrator-level capabilities).
Event History
Frequently Asked Questions
Who can exploit this issue?
A user who already holds the MultiVendorX vendor role can exploit it. The issue allows that user to grant the vendor role administrator-level capabilities and take over the WordPress site.
Which versions are affected?
MultiVendorX versions 5.0.0 through 5.0.15 are affected. Version 5.0.16 or later is not described as affected.
What should be done if an immediate update is not possible?
The provided information does not specify a workaround. Because exploitation requires the MultiVendorX vendor role, review and restrict vendor-role account access until the plugin can be updated.