VYPR
Low severity2.7NVD Advisory· Published Aug 5, 2026· Updated Aug 26, 2026

CVE-2026-16746

CVE-2026-16746

Description

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1