{"id":"CVE-2026-108695","title":"MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint","summary":"MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. Attackers with the store_owner role can send P…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","cwe":["CWE-863"],"published":"2026-10-11","updated":"2026-10-11","sourceUpdated":"2026-10-11T02:16:37.957","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108695","references":[{"url":"https://github.com/multivendorx/multivendorx","label":"disclosure@vulncheck.com"},{"url":"https://github.com/multivendorx/multivendorx/blob/8a717799b02f698e4b2b61a282062a41fbe15183/plugins/multivendorx/classes/RestAPI/Controllers/Settings.php#L157-L172","label":"disclosure@vulncheck.com"},{"url":"https://github.com/multivendorx/multivendorx/blob/8a717799b02f698e4b2b61a282062a41fbe15183/plugins/multivendorx/classes/RestAPI/Controllers/Settings.php#L77-L80","label":"disclosure@vulncheck.com"},{"url":"https://github.com/multivendorx/multivendorx/issues/2375","label":"disclosure@vulncheck.com"},{"url":"https://wordpress.org/plugins/dc-woocommerce-multi-vendor/","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/multivendorx-through-5.0.19-incorrect-authorization-via-settings-rest-endpoint","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-10-11T02:38:44.035Z","slug":"CVE-2026-108695","body":"## Overview\n\nMultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. Attackers with the store_owner role can send POST requests to /wp-json/multivendorx/v1/settings, gated only by edit_stores, to overwrite commission, payout, and onboarding settings.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}