LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-16605

Published
CVSS7.2
Severityhigh
WeaknessCWE-862
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-16605

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-16605.