MultiVendorX Incorrect Authorization Vulnerability
The MultiVendorX WordPress plugin through version 5.0.19 contains an authorization bypass vulnerability allowing authenticated store owners to modify global marketplace settings via the REST API.
CVE search metadata
CVE search record: CVE-2026-108695. Severity: high. CVSS: 7.1. KEV: no. Product: MultiVendorX (<= 5.0.19). Brief: MultiVendorX Incorrect Authorization Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-multivendorx-auth-bypass/
The MultiVendorX WordPress plugin (versions 5.0.19 and earlier) contains an incorrect authorization vulnerability in its settings REST API. The plugin fails to correctly validate the permissions required for administrative configuration changes. Specifically, the endpoint /wp-json/multivendorx/v1/settings relies solely on the 'edit_stores' capability, which is assigned to the 'store_owner' role. This vulnerability allows an authenticated vendor account to escalate their privilege level to modify sensitive marketplace-wide configurations, such as commission structures, payout methods, and onboarding workflows. This is a critical risk for marketplace operators as it enables store owners to potentially misappropriate funds or disrupt the operational integrity of the entire platform. Defenders should audit access to the identified API endpoint and prioritize updating to the patched version of the plugin as soon as it becomes available.
Attack Chain
- Attacker registers or gains access to a WordPress account with the 'store_owner' role.
- Attacker performs authenticated session management to interact with the WordPress REST API.
- Attacker identifies the target REST endpoint at /wp-json/multivendorx/v1/settings.
- Attacker crafts a POST request to the target endpoint containing modified JSON configuration data.
- The plugin application validates the 'edit_stores' capability, which the attacker possesses.
- The plugin fails to perform a secondary check for administrative privileges.
- The application processes the POST request and updates global settings in the WordPress database.
- Final objective is achieved: unauthorized modification of marketplace commission and payout settings.
Impact
Successful exploitation allows a low-privileged 'store_owner' to alter global settings for an entire multi-vendor marketplace. This can lead to unauthorized financial gains through modified commission structures, diversion of platform payouts, or the degradation of platform service through manipulated onboarding configurations. The number of impacted installations is potentially high given the widespread use of MultiVendorX in WordPress-based marketplace ecosystems.
Recommendation
- Monitor WordPress access logs for POST requests to /wp-json/multivendorx/v1/settings originating from accounts with the 'store_owner' role.
- Audit administrative settings changes within the WordPress database to identify unauthorized updates to commission or payout fields.
- Apply updates to the MultiVendorX plugin immediately upon the release of version 5.0.20 or higher addressing CVE-2026-108695.
Immediate actions
Deploy Sigma detection rule to monitor for POST requests to the settings endpoint
Mitigations
Upgrade MultiVendorX to the first available secure version (5.0.20 or later)
CVE-2026-108695
Detection coverage 1
Detect Unauthorized MultiVendorX Settings Modification
highDetects POST requests to the MultiVendorX settings REST endpoint which may indicate exploitation of CVE-2026-108695
Detection queries are available on the platform. Get full rules →