Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX
CVE-2026-81792

6.5MEDIUM

What is CVE-2026-81792?

A vulnerability exists in the Product Catalog Enquiry for WooCommerce plugin by MultiVendorX affecting versions 6.1.4 and below, allowing unauthenticated users to escalate privileges. Exploiting this issue could enable attackers to access restricted functionalities without proper authorization, potentially compromising sensitive information and system integrity.

Affected Version(s)

Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peng Zhou | Patchstack Bug Bounty Program
.