{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/multivendorx--5.0.19/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:multivendorx:multivendorx:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-108695"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MultiVendorX (\u003c= 5.0.19)"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin","authorization-bypass","cve-2026-108695"],"_cs_type":"advisory","_cs_vendors":["MultiVendorX"],"content_html":"\u003cp\u003eThe MultiVendorX WordPress plugin (versions 5.0.19 and earlier) contains an incorrect authorization vulnerability in its settings REST API. The plugin fails to correctly validate the permissions required for administrative configuration changes. Specifically, the endpoint /wp-json/multivendorx/v1/settings relies solely on the 'edit_stores' capability, which is assigned to the 'store_owner' role. This vulnerability allows an authenticated vendor account to escalate their privilege level to modify sensitive marketplace-wide configurations, such as commission structures, payout methods, and onboarding workflows. This is a critical risk for marketplace operators as it enables store owners to potentially misappropriate funds or disrupt the operational integrity of the entire platform. Defenders should audit access to the identified API endpoint and prioritize updating to the patched version of the plugin as soon as it becomes available.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker registers or gains access to a WordPress account with the 'store_owner' role.\u003c/li\u003e\n\u003cli\u003eAttacker performs authenticated session management to interact with the WordPress REST API.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the target REST endpoint at /wp-json/multivendorx/v1/settings.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a POST request to the target endpoint containing modified JSON configuration data.\u003c/li\u003e\n\u003cli\u003eThe plugin application validates the 'edit_stores' capability, which the attacker possesses.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to perform a secondary check for administrative privileges.\u003c/li\u003e\n\u003cli\u003eThe application processes the POST request and updates global settings in the WordPress database.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved: unauthorized modification of marketplace commission and payout settings.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a low-privileged 'store_owner' to alter global settings for an entire multi-vendor marketplace. This can lead to unauthorized financial gains through modified commission structures, diversion of platform payouts, or the degradation of platform service through manipulated onboarding configurations. The number of impacted installations is potentially high given the widespread use of MultiVendorX in WordPress-based marketplace ecosystems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor WordPress access logs for POST requests to /wp-json/multivendorx/v1/settings originating from accounts with the 'store_owner' role.\u003c/li\u003e\n\u003cli\u003eAudit administrative settings changes within the WordPress database to identify unauthorized updates to commission or payout fields.\u003c/li\u003e\n\u003cli\u003eApply updates to the MultiVendorX plugin immediately upon the release of version 5.0.20 or higher addressing CVE-2026-108695.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T03:58:13Z","date_published":"2026-10-11T03:58:13Z","id":"https://feed.craftedsignal.io/briefs/2026-10-multivendorx-auth-bypass/","summary":"The MultiVendorX WordPress plugin through version 5.0.19 contains an authorization bypass vulnerability allowing authenticated store owners to modify global marketplace settings via the REST API.","title":"MultiVendorX Incorrect Authorization Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-multivendorx-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - MultiVendorX (\u003c= 5.0.19)","version":"https://jsonfeed.org/version/1.1"}