Skip to content
Threat Feed
high advisory

MultiVendorX Incorrect Authorization Vulnerability

The MultiVendorX WordPress plugin through version 5.0.19 contains an authorization bypass vulnerability allowing authenticated store owners to modify global marketplace settings via the REST API.

CVE search metadata

CVE search record: CVE-2026-108695. Severity: high. CVSS: 7.1. KEV: no. Product: MultiVendorX (<= 5.0.19). Brief: MultiVendorX Incorrect Authorization Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-multivendorx-auth-bypass/

The MultiVendorX WordPress plugin (versions 5.0.19 and earlier) contains an incorrect authorization vulnerability in its settings REST API. The plugin fails to correctly validate the permissions required for administrative configuration changes. Specifically, the endpoint /wp-json/multivendorx/v1/settings relies solely on the 'edit_stores' capability, which is assigned to the 'store_owner' role. This vulnerability allows an authenticated vendor account to escalate their privilege level to modify sensitive marketplace-wide configurations, such as commission structures, payout methods, and onboarding workflows. This is a critical risk for marketplace operators as it enables store owners to potentially misappropriate funds or disrupt the operational integrity of the entire platform. Defenders should audit access to the identified API endpoint and prioritize updating to the patched version of the plugin as soon as it becomes available.

Attack Chain

  1. Attacker registers or gains access to a WordPress account with the 'store_owner' role.
  2. Attacker performs authenticated session management to interact with the WordPress REST API.
  3. Attacker identifies the target REST endpoint at /wp-json/multivendorx/v1/settings.
  4. Attacker crafts a POST request to the target endpoint containing modified JSON configuration data.
  5. The plugin application validates the 'edit_stores' capability, which the attacker possesses.
  6. The plugin fails to perform a secondary check for administrative privileges.
  7. The application processes the POST request and updates global settings in the WordPress database.
  8. Final objective is achieved: unauthorized modification of marketplace commission and payout settings.

Impact

Successful exploitation allows a low-privileged 'store_owner' to alter global settings for an entire multi-vendor marketplace. This can lead to unauthorized financial gains through modified commission structures, diversion of platform payouts, or the degradation of platform service through manipulated onboarding configurations. The number of impacted installations is potentially high given the widespread use of MultiVendorX in WordPress-based marketplace ecosystems.

Recommendation

  • Monitor WordPress access logs for POST requests to /wp-json/multivendorx/v1/settings originating from accounts with the 'store_owner' role.
  • Audit administrative settings changes within the WordPress database to identify unauthorized updates to commission or payout fields.
  • Apply updates to the MultiVendorX plugin immediately upon the release of version 5.0.20 or higher addressing CVE-2026-108695.

Immediate actions

Deploy Sigma detection rule to monitor for POST requests to the settings endpoint

Detection Engineering 24h

Mitigations

Upgrade MultiVendorX to the first available secure version (5.0.20 or later)

immediate IT Operations

CVE-2026-108695

Detection coverage 1

Detect Unauthorized MultiVendorX Settings Modification

high

Detects POST requests to the MultiVendorX settings REST endpoint which may indicate exploitation of CVE-2026-108695

sigma tactics: privilege-escalation techniques: T1068 sources: webserver

Detection queries are available on the platform. Get full rules →