Vendor
The MultiVendorX WordPress plugin through version 5.0.19 contains an authorization bypass vulnerability allowing authenticated store owners to modify global marketplace settings via the REST API.