SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-74925

HIGH · CVSS 7.2 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The MultiVendorX WordPress plugin prior to version 5.0.16 is vulnerable due to insufficient restrictions on role and capability settings, enabling users with the vendor role to escalate their privileges to administrator-level. This flaw could lead to unauthorized access and potential site takeover, posing a significant risk to WordPress installations utilizing this plugin. WordPress site administrators and security teams should prioritize updating to the latest version to mitigate this high-severity vulnerability.

CVE
CVE-2026-74925
Severity
HIGH
CVSS
7.2
EPSS
0.26%
WordPress

Original NVD Description

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.