What is CVE-2026-16746?
The MultiVendorX WordPress plugin before version 5.0.11 fails to verify that the requested store belongs to the current user in one of its REST API endpoints. This allows any vendor-level user to read other vendors' commission and financial data. Immediate update to version 5.0.11 or later is recommended.
Azərbaycanca: MultiVendorX WordPress plaqini 5.0.11 versiyasından əvvəl REST API endpoint-lərində təhlükəsizlik yoxlamasını düzgün aparmır. Bu zəiflik səbəbindən istənilən vendor səviyyəli istifadəçi digər vendorların komissiya və maliyyə məlumatlarını oxuya bilər. Plaqini dərhal 5.0.11 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which plugin is affected by CVE-2026-16746 and what versions are vulnerable?
The vulnerability affects all versions of the MultiVendorX WordPress plugin before version 5.0.11.
What type of data can a vendor-level user access by exploiting CVE-2026-16746?
Through this vulnerability, any vendor-level user can read other vendors' commission and financial data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.