Junglewise Threat Intelligence

CVE-2026-81792: MultiVendorX Product Catalog Enquiry privilege escalation

CVE-2026-81792 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Vendors: MultiVendorX.

Executive brief

Product Catalog Enquiry for WooCommerce is a WordPress plugin that allows store operators to manage customer inquiries about products. An unauthenticated attacker can exploit an incorrect privilege assignment flaw to gain administrator access to the WooCommerce site, enabling full control over the store, customer data, and transactions.

Technical details

The plugin contains an incorrect privilege assignment vulnerability that permits unauthenticated users to escalate privileges to administrator. The flaw allows a low-privilege or unauthenticated attacker to bypass authorization checks and assume admin role, gaining full control over the WordPress installation. No patch is currently available; mitigation via WAF rules is recommended.

Affected products

  • MultiVendorX Product Catalog Enquiry for WooCommerce through 6.1.5

Timeline

  • 2026-09-07: disclosed
  • 2026-09-08: advisory

References