Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy < 5.0.14 - Unauthenticated Information Exposure
medium
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 5.0.14. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 5.0.14
- Fixed in:
- 5.0.14
- Disclosed:
- Aug 24, 2026
CVE-2026-16575 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy < 5.0.14 - Missing Authorization
medium
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized access in all versions up to 5.0.14. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with custom role-lev...
- CVSS:
- 4.3
- Affected:
- up to 5.0.14
- Fixed in:
- 5.0.14
- Disclosed:
- Aug 24, 2026
CVE-2026-16577 on NVD →
Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation
high
The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the `/dokan/v...
- CVSS:
- 8.8
- Affected:
- up to 5.0.2
- Fixed in:
- 5.0.3
- Disclosed:
- Aug 4, 2026
CVE-2026-8761 on NVD →
Dokan <= 5.0.10 - Insecure Direct Object Reference to Authenticated (Vendor+) Cross-Vendor Downloadable Product Access Grant
medium
The Dokan plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.10. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with vendor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.0.10
- Fixed in:
- 5.0.11
- Disclosed:
- Aug 3, 2026
CVE-2026-16574 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.10 - Missing Authorization
medium
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0.10. This makes it possible for authenticated attackers, with custom role-...
- CVSS:
- 4.3
- Affected:
- up to 5.0.10
- Fixed in:
- 5.0.11
- Disclosed:
- Jul 29, 2026
CVE-2026-66699 on NVD →
Dokan <= 5.0.8 - Insecure Direct Object Reference to Authenticated (Vendor+) Arbitrary Order Status Modification
medium
The Dokan plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with vendor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.0.8
- Fixed in:
- 5.0.9
- Disclosed:
- Jul 24, 2026
CVE-2026-16564 on NVD →
Dokan <= 5.0.8 - Insecure Direct Object Reference to Authenticated (Vendor+) Cross-Vendor Product Attribute Modification
medium
The Dokan plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with vendor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.0.8
- Fixed in:
- 5.0.9
- Disclosed:
- Jul 24, 2026
CVE-2026-16565 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting
high
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...
- CVSS:
- 7.2
- Affected:
- up to 5.0.6
- Fixed in:
- 5.0.7
- Disclosed:
- Jul 10, 2026
CVE-2026-57706 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter
medium
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for...
- CVSS:
- 4.3
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.5
- Disclosed:
- Jun 26, 2026
CVE-2026-11987 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU
medium
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.5
- Disclosed:
- Jun 26, 2026
CVE-2026-11783 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers
medium
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note, add_shipping_tracking_info, grant_acce...
- CVSS:
- 4.3
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.4
- Disclosed:
- Jun 17, 2026
CVE-2026-10023 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.2 - Authenticated (Customer+) Privilege Escalation
high
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.2. This makes it possible for authenticated attackers, with Custom-level access and above, to elevate their privileg...
- CVSS:
- 8.8
- Affected:
- up to 5.0.2
- Fixed in:
- 5.0.3
- Disclosed:
- Jun 3, 2026
CVE-2026-49780 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API Endpoint
medium
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due to the 'prepare_reviews_for_response' method including reviewer email...
- CVSS:
- 5.3
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.2
- Disclosed:
- May 1, 2026
CVE-2026-3504 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Missing Authorization
medium
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.4. This makes it possible for authenticated attackers, with Subscribe...
- CVSS:
- 4.3
- Affected:
- up to 4.2.4
- Fixed in:
- 4.2.5
- Disclosed:
- Mar 16, 2026
CVE-2026-24359 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 4.2.5
unknown
[en] The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to missing validation on a user-controlled...
- Affected:
- up to 4.2.5
- Fixed in:
- 4.2.5
- Disclosed:
- Jan 20, 2026
CVE-2025-14977 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure
high
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to missing validation on a user-controlled key....
- CVSS:
- 8.1
- Affected:
- up to 4.2.4
- Fixed in:
- 4.2.5
- Disclosed:
- Jan 19, 2026
CVE-2025-14977 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] <= 4.1.2 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <= 4.1.2.
- Affected:
- up to 4.1.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-53425 on NVD →
Dokan <= 4.1.3 - Authenticated (Shop Manager+) Privilege Escalation
high
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to gain access to a...
- CVSS:
- 7.2
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- Sep 20, 2025
CVE-2025-53425 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.6.6
unknown
[en] The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.
- Affected:
- up to 3.6.6
- Fixed in:
- 3.6.6
- Disclosed:
- Jan 16, 2024
CVE-2022-3194 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.13
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy...
- Affected:
- up to 3.7.13
- Fixed in:
- 3.7.13
- Disclosed:
- Dec 20, 2023
CVE-2023-26525 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.20
unknown
[en] Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.19.
- Affected:
- up to 3.7.20
- Fixed in:
- 3.7.20
- Disclosed:
- Dec 19, 2023
CVE-2023-34382 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.0.9
unknown
[en] The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers to trigger an order export via a forged request grante...
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.9
- Disclosed:
- Jul 1, 2023
CVE-2020-36748 on NVD →
Dokan <=3.7.19 - Authenticated(Shop Manager+) PHP Object Injection via create_dummy_vendor
medium
The Dokan plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7.19 via deserialization of untrusted input via the 'create_dummy_vendor' function called by the 'import' REST API endpoint. This allows authenticated attackers with Shop Manager privileges or above to inject a PHP...
- CVSS:
- 6.6
- Affected:
- up to 3.7.20
- Fixed in:
- 3.7.20
- Disclosed:
- Jun 7, 2023
CVE-2023-34382 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.20
unknown
The Dokan plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7.19 via deserialization of untrusted input via the 'create_dummy_vendor' function called by the 'import' REST API endpoint. This allows authenticated attackers with Shop Manager privileges or above to inject a PHP...
- Affected:
- up to 3.7.20
- Fixed in:
- 3.7.20
- Disclosed:
- Jun 7, 2023
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.2.1
unknown
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.1
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Dokan <= 3.7.12 - Authenticated (Vendor+) SQL Injection
high
The Dokan plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and including, 3.7.12 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with vendor-level...
- CVSS:
- 7.2
- Affected:
- up to 3.7.12
- Fixed in:
- 3.7.13
- Disclosed:
- Mar 2, 2023
CVE-2023-26525 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.6
unknown
[en] The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.6
- Disclosed:
- Dec 12, 2022
CVE-2022-3915 on NVD →
Dokan <= 3.7.5 - Unauthenticated SQL Injection
critical
The Dokan plugin for WordPress is vulnerable to SQL Injection via the ‘user_ids’ parameter in versions up to, and including, 3.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query on an AJAX action that is available to unprivileged users. This make...
- CVSS:
- 9.8
- Affected:
- up to 3.7.5
- Fixed in:
- 3.7.6
- Disclosed:
- Nov 21, 2022
CVE-2022-3915 on NVD →
Dokan <= 3.6.5 - Cross-Site Request Forgery
high
The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.5. This is due to missing or incorrect nonce validation on the setup_wizard function. This makes it possible for unauthenticated attackers to change settings in the setup process, via forged request granted...
- CVSS:
- 8.8
- Affected:
- up to 3.6.5
- Fixed in:
- 3.6.6
- Disclosed:
- Sep 28, 2022
CVE-2022-3194 on NVD →
Dokan <= 3.6.3 - Authenticated (Vendor+) Stored Cross-Site Scripting
medium
The Dokan plugin for WordPress is vulnerable to Stored Cross-Site Scripting via product reviews in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with vendor permissions and above, to inject arbitrary web scripts in pa...
- CVSS:
- 5.5
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.4
- Disclosed:
- Sep 13, 2022
CVE-2022-3194 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.2.1
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by NintechNet in WordPress Dokan plugin (versions <= 3.2.0).
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.1
- Disclosed:
- Mar 1, 2021
Dokan <= 3.0.8 - Cross-Site Request Forgery Bypass
medium
The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers to trigger an order export via a forged request granted the...
- CVSS:
- 4.3
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.9
- Disclosed:
- Sep 16, 2020
CVE-2020-36748 on NVD →
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.0.9
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Dokan plugin (versions <= 3.0.8).
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.9
- Disclosed:
- Sep 16, 2020
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.2.1
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.1