PoC Index

CVE-2026-16605

HIGH 7.2EPSS 0.3%

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.32% chance of exploitation in the next 30 days, 24th percentile
Published
2026-08-05

Proof-of-concept exploits (1)

References

Related