Zero Day Monitor
ZDM
Dashboard
Vulnerabilities
Trending
Zero-Days
News
About
Login
← Back to list
7.5
CVE-2026-66441
KEV
EXPLOITED
multivendorx · multivendorx
WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability
Description
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
Affected Products
Vendor
Product
Versions
multivendorx
multivendorx
n/a
References
https://patchstack.com/database/wordpress/plugin/dc-woocommerce-multi-vendor/vulnerability/wordpress-multivendorx-plugin-5-0-10-broken-access-control-vulnerability?_s_id=cve
(vdb-entry)
Related News (1 articles)
Tier C
VulDB
2h ago
CVE-2026-66441 | MultiVendorX Plugin up to 5.0.10 on WordPress access control
→ No new info (linked only)
CVSS 3.1
7.5
HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV
✅ Yes
Actively exploited
✅ Yes
CWE
CWE-862
Published
Aug 13, 2026
Trending Score
106
🔥
Source articles
1
Independent
1
Info Completeness
0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack
Community Vote
0
Login to vote
0 upvotes
0 downvotes
No votes yet
Related CVEs (1)
MEDIUM
CVE-2026-61945
WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Exposure vulnerability
Trending: 2
Pin to Dashboard
Verification
State:
unverified
Confidence:
0%
Vulnerability Timeline
CVE Published
Aug 13, 2026
Added to CISA KEV
Aug 13, 2026
Discovered by ZDM
Aug 13, 2026
Actively Exploited
Aug 13, 2026
CVE-2026-66441: WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability — Zero Day Monitor