WordPress Plugin Vulnerabilities

MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator

Description

The plugin does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Philipp Doblhofer
Submitter
Philipp Doblhofer
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-09 (about 2 days ago)
Added
2026-09-09 (about 1 day ago)
Last Updated
2026-09-09 (about 1 day ago)

Other