What is CVE-2026-16605?
The MultiVendorX WordPress plugin before 5.0.11 lacks verification that a store targeted via its REST API belongs to the requesting vendor. This allows an authenticated vendor to view, take over, modify, or delete any other vendor's store. Immediate plugin update and restricting REST API access are required.
Azərbaycanca: MultiVendorX WordPress plaginində (5.0.11-dən əvvəlki versiyalar) autentifikasiya olunmuş satıcıya təsdiqləmə çatışmazlığı aşkar edilib. Bu boşluq REST API vasitəsilə istənilən satıcı mağazasına baxmaq, onu ələ keçirmək, dəyişdirmək və ya silmək imkanı verir. Dərhal plagin yenilənməli və REST API girişləri məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-863
FAQ1
What actions can an authenticated vendor perform by exploiting CVE-2026-16605 in the MultiVendorX plugin?
An authenticated vendor can view, take over, modify, or delete any other vendor's store via the REST API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.