CVE-2026-16746 UNKNOWN

CVE-2026-16746

Published: 2026-08-05

Description

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…