plugin

Dokan Lite Vulnerabilities

34 known security issues reported for the Dokan Lite WordPress plugin. Most recent disclosed Aug 24, 2026.

1 critical 7 high 14 medium

Running Dokan Lite on your site? Check whether your installed version is affected.

Scan your site free

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy < 5.0.14 - Unauthenticated Information Exposure

medium

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 5.0.14. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 5.0.14
Fixed in:
5.0.14
Disclosed:
Aug 24, 2026

CVE-2026-16575 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy < 5.0.14 - Missing Authorization

medium

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized access in all versions up to 5.0.14. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with custom role-lev...

CVSS:
4.3
Affected:
up to 5.0.14
Fixed in:
5.0.14
Disclosed:
Aug 24, 2026

CVE-2026-16577 on NVD →

Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation

high

The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the `/dokan/v...

CVSS:
8.8
Affected:
up to 5.0.2
Fixed in:
5.0.3
Disclosed:
Aug 4, 2026

CVE-2026-8761 on NVD →

Dokan <= 5.0.10 - Insecure Direct Object Reference to Authenticated (Vendor+) Cross-Vendor Downloadable Product Access Grant

medium

The Dokan plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.10. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with vendor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.0.10
Fixed in:
5.0.11
Disclosed:
Aug 3, 2026

CVE-2026-16574 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.10 - Missing Authorization

medium

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0.10. This makes it possible for authenticated attackers, with custom role-...

CVSS:
4.3
Affected:
up to 5.0.10
Fixed in:
5.0.11
Disclosed:
Jul 29, 2026

CVE-2026-66699 on NVD →

Dokan <= 5.0.8 - Insecure Direct Object Reference to Authenticated (Vendor+) Arbitrary Order Status Modification

medium

The Dokan plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with vendor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.0.8
Fixed in:
5.0.9
Disclosed:
Jul 24, 2026

CVE-2026-16564 on NVD →

Dokan <= 5.0.8 - Insecure Direct Object Reference to Authenticated (Vendor+) Cross-Vendor Product Attribute Modification

medium

The Dokan plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with vendor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.0.8
Fixed in:
5.0.9
Disclosed:
Jul 24, 2026

CVE-2026-16565 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting

high

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...

CVSS:
7.2
Affected:
up to 5.0.6
Fixed in:
5.0.7
Disclosed:
Jul 10, 2026

CVE-2026-57706 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter

medium

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for...

CVSS:
4.3
Affected:
up to 5.0.4
Fixed in:
5.0.5
Disclosed:
Jun 26, 2026

CVE-2026-11987 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU

medium

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 5.0.4
Fixed in:
5.0.5
Disclosed:
Jun 26, 2026

CVE-2026-11783 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers

medium

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note, add_shipping_tracking_info, grant_acce...

CVSS:
4.3
Affected:
up to 5.0.3
Fixed in:
5.0.4
Disclosed:
Jun 17, 2026

CVE-2026-10023 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.2 - Authenticated (Customer+) Privilege Escalation

high

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.2. This makes it possible for authenticated attackers, with Custom-level access and above, to elevate their privileg...

CVSS:
8.8
Affected:
up to 5.0.2
Fixed in:
5.0.3
Disclosed:
Jun 3, 2026

CVE-2026-49780 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API Endpoint

medium

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due to the 'prepare_reviews_for_response' method including reviewer email...

CVSS:
5.3
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
May 1, 2026

CVE-2026-3504 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Missing Authorization

medium

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.4. This makes it possible for authenticated attackers, with Subscribe...

CVSS:
4.3
Affected:
up to 4.2.4
Fixed in:
4.2.5
Disclosed:
Mar 16, 2026

CVE-2026-24359 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 4.2.5

unknown

[en] The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to missing validation on a user-controlled...

Affected:
up to 4.2.5
Fixed in:
4.2.5
Disclosed:
Jan 20, 2026

CVE-2025-14977 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure

high

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to missing validation on a user-controlled key....

CVSS:
8.1
Affected:
up to 4.2.4
Fixed in:
4.2.5
Disclosed:
Jan 19, 2026

CVE-2025-14977 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] <= 4.1.2 (unfixed)

unknown

[en] Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <= 4.1.2.

Affected:
up to 4.1.2
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-53425 on NVD →

Dokan <= 4.1.3 - Authenticated (Shop Manager+) Privilege Escalation

high

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to gain access to a...

CVSS:
7.2
Affected:
up to 4.1.3
Fixed in:
4.1.4
Disclosed:
Sep 20, 2025

CVE-2025-53425 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.6.6

unknown

[en] The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.

Affected:
up to 3.6.6
Fixed in:
3.6.6
Disclosed:
Jan 16, 2024

CVE-2022-3194 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.13

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy...

Affected:
up to 3.7.13
Fixed in:
3.7.13
Disclosed:
Dec 20, 2023

CVE-2023-26525 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.20

unknown

[en] Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.19.

Affected:
up to 3.7.20
Fixed in:
3.7.20
Disclosed:
Dec 19, 2023

CVE-2023-34382 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.0.9

unknown

[en] The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers to trigger an order export via a forged request grante...

Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Jul 1, 2023

CVE-2020-36748 on NVD →

Dokan <=3.7.19 - Authenticated(Shop Manager+) PHP Object Injection via create_dummy_vendor

medium

The Dokan plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7.19 via deserialization of untrusted input via the 'create_dummy_vendor' function called by the 'import' REST API endpoint. This allows authenticated attackers with Shop Manager privileges or above to inject a PHP...

CVSS:
6.6
Affected:
up to 3.7.20
Fixed in:
3.7.20
Disclosed:
Jun 7, 2023

CVE-2023-34382 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.20

unknown

The Dokan plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7.19 via deserialization of untrusted input via the 'create_dummy_vendor' function called by the 'import' REST API endpoint. This allows authenticated attackers with Shop Manager privileges or above to inject a PHP...

Affected:
up to 3.7.20
Fixed in:
3.7.20
Disclosed:
Jun 7, 2023

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.2.1

unknown
Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Dokan <= 3.7.12 - Authenticated (Vendor+) SQL Injection

high

The Dokan plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and including, 3.7.12 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with vendor-level...

CVSS:
7.2
Affected:
up to 3.7.12
Fixed in:
3.7.13
Disclosed:
Mar 2, 2023

CVE-2023-26525 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.6

unknown

[en] The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

Affected:
up to 3.7.6
Fixed in:
3.7.6
Disclosed:
Dec 12, 2022

CVE-2022-3915 on NVD →

Dokan <= 3.7.5 - Unauthenticated SQL Injection

critical

The Dokan plugin for WordPress is vulnerable to SQL Injection via the ‘user_ids’ parameter in versions up to, and including, 3.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query on an AJAX action that is available to unprivileged users. This make...

CVSS:
9.8
Affected:
up to 3.7.5
Fixed in:
3.7.6
Disclosed:
Nov 21, 2022

CVE-2022-3915 on NVD →

Dokan <= 3.6.5 - Cross-Site Request Forgery

high

The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.5. This is due to missing or incorrect nonce validation on the setup_wizard function. This makes it possible for unauthenticated attackers to change settings in the setup process, via forged request granted...

CVSS:
8.8
Affected:
up to 3.6.5
Fixed in:
3.6.6
Disclosed:
Sep 28, 2022

CVE-2022-3194 on NVD →

Dokan <= 3.6.3 - Authenticated (Vendor+) Stored Cross-Site Scripting

medium

The Dokan plugin for WordPress is vulnerable to Stored Cross-Site Scripting via product reviews in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with vendor permissions and above, to inject arbitrary web scripts in pa...

CVSS:
5.5
Affected:
up to 3.6.3
Fixed in:
3.6.4
Disclosed:
Sep 13, 2022

CVE-2022-3194 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.2.1

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by NintechNet in WordPress Dokan plugin (versions <= 3.2.0).

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Mar 1, 2021

Dokan <= 3.0.8 - Cross-Site Request Forgery Bypass

medium

The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers to trigger an order export via a forged request granted the...

CVSS:
4.3
Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Sep 16, 2020

CVE-2020-36748 on NVD →

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.0.9

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Dokan plugin (versions <= 3.0.8).

Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Sep 16, 2020

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.2.1

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 3.2.1
Fixed in:
3.2.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database