CVE-2026-66441

WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.


We have discovered 290 live websites that are affected by CVE-2026-66441.

Run a Free Instant Scan




Affected Software

Product  Dc Woocommerce Multi Vendor
Category Wordpress Plugins
Vulnerable Domains290 live websites (100% of Dc Woocommerce Multi Vendor install base)
Vulnerable Versions
  • from 0 through 5.0.10
Vulnerable Versions Count54 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • Uma Mo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66441
United States95 websites



France23 websites
Germany18 websites
Cyprus17 websites
GB10 websites
India9 websites
Brazil8 websites
South Africa7 websites
Italy7 websites
Russia6 websites

Website Distribution by TLD

Number of websites using CVE-2026-66441
.com161 websites
.net9 websites
.fr9 websites
.com.br7 websites
.it6 websites
.org5 websites
.co.uk5 websites
.nl4 websites
.ru4 websites
.de3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66441

Top websites that are affected by CVE-2026-66441. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.**.il Israel**,***
**********.com Malaysia***,***
*************.info GB***,***
*****************.**.uk United States***,***
**********.com United States*,***,***
****************.com India*,***,***
************.com France*,***,***
***************.com France*,***,***
**********.com United States*,***,***
**********************.fr France*,***,***
See full domain list

FAQ

CVE-2026-66441 is Missing Authorization in Dc Woocommerce Multi Vendor
A total of 290 websites have been identified as vulnerable to CVE-2026-66441, based on global website indexing conducted by WebTechSurvey.
The Dc Woocommerce Multi Vendor is affected by the CVE-2026-66441 vulnerability.
Dc Woocommerce Multi Vendor versions up to and including 5.0.10 are vulnerable to CVE-2026-66441.