WordPress Plugin Vulnerabilities

MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator

Description

The plugin does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Philipp Doblhofer
Submitter
Philipp Doblhofer
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-09 (about 22 days ago)
Added
2026-09-09 (about 21 days ago)
Last Updated
2026-09-09 (about 21 days ago)

Other