← Back to search

CVE-2026-16746

2.7 LOW

Published 2026-08-05 · Updated 2026-08-06

AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.

NVD description

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-639

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.