Unrated severityNVD Advisory· Published Sep 11, 2026
CVE-2026-74925
CVE-2026-74925
Description
The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <5.0.16
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.