Executive brief
MultiVendorX is a WordPress plugin that enables multi-vendor marketplace functionality. A vendor-role user can escalate their privileges to full site administrator by modifying role and capability settings, potentially enabling complete site takeover. Organizations using this plugin for vendor management are at risk of loss of administrative control and data compromise.
Technical details
The vulnerability is a privilege escalation (CWE-269) affecting the plugin's role and capability management functionality. The plugin fails to enforce proper authorization checks when updating role capabilities, allowing users holding the vendor role to grant themselves administrator-level permissions. Exploitation requires authentication as a vendor-role user, but no additional user interaction is needed. An authenticated vendor can directly call the affected functionality to add administrative capabilities to their role, resulting in full site compromise. Fixed in version 5.0.16.
Affected products
- MultiVendorX MultiVendorX 5.0.0 to 5.0.15
Timeline
- 2026-09-09: disclosed
- 2026-09-11: patched: Fixed in version 5.0.16