<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MultiVendorX (&lt;= 5.0.19) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/multivendorx--5.0.19/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 03:58:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/multivendorx--5.0.19/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>MultiVendorX Incorrect Authorization Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-10-multivendorx-auth-bypass/</link><pubDate>Sun, 11 Oct 2026 03:58:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-multivendorx-auth-bypass/</guid><description>The MultiVendorX WordPress plugin through version 5.0.19 contains an authorization bypass vulnerability allowing authenticated store owners to modify global marketplace settings via the REST API.</description><content:encoded><![CDATA[<p>The MultiVendorX WordPress plugin (versions 5.0.19 and earlier) contains an incorrect authorization vulnerability in its settings REST API. The plugin fails to correctly validate the permissions required for administrative configuration changes. Specifically, the endpoint /wp-json/multivendorx/v1/settings relies solely on the 'edit_stores' capability, which is assigned to the 'store_owner' role. This vulnerability allows an authenticated vendor account to escalate their privilege level to modify sensitive marketplace-wide configurations, such as commission structures, payout methods, and onboarding workflows. This is a critical risk for marketplace operators as it enables store owners to potentially misappropriate funds or disrupt the operational integrity of the entire platform. Defenders should audit access to the identified API endpoint and prioritize updating to the patched version of the plugin as soon as it becomes available.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker registers or gains access to a WordPress account with the 'store_owner' role.</li>
<li>Attacker performs authenticated session management to interact with the WordPress REST API.</li>
<li>Attacker identifies the target REST endpoint at /wp-json/multivendorx/v1/settings.</li>
<li>Attacker crafts a POST request to the target endpoint containing modified JSON configuration data.</li>
<li>The plugin application validates the 'edit_stores' capability, which the attacker possesses.</li>
<li>The plugin fails to perform a secondary check for administrative privileges.</li>
<li>The application processes the POST request and updates global settings in the WordPress database.</li>
<li>Final objective is achieved: unauthorized modification of marketplace commission and payout settings.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a low-privileged 'store_owner' to alter global settings for an entire multi-vendor marketplace. This can lead to unauthorized financial gains through modified commission structures, diversion of platform payouts, or the degradation of platform service through manipulated onboarding configurations. The number of impacted installations is potentially high given the widespread use of MultiVendorX in WordPress-based marketplace ecosystems.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor WordPress access logs for POST requests to /wp-json/multivendorx/v1/settings originating from accounts with the 'store_owner' role.</li>
<li>Audit administrative settings changes within the WordPress database to identify unauthorized updates to commission or payout fields.</li>
<li>Apply updates to the MultiVendorX plugin immediately upon the release of version 5.0.20 or higher addressing CVE-2026-108695.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>plugin</category><category>authorization-bypass</category><category>cve-2026-108695</category></item></channel></rss>