SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74927

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The MultiVendorX WordPress plugin prior to version 5.0.15 is vulnerable due to inadequate authorization controls on a REST API listing route, enabling unauthenticated users to access sensitive vendor information, including contact details, payout amounts, and administrative notes. This exposure could lead to data leakage and potential exploitation of vendor accounts. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-74927
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%
WordPress

Original NVD Description

The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications.