Unrated severityNVD Advisory· Published Aug 5, 2026
MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint
CVE-2026-16746
Description
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.
Affected products
1- Range: <5.0.11
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/721033a0-b0bb-4a64-a99a-12ac416b20fd/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.