sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total20
Critical2
High5
Medium12
Reset
Showing 1-20 of 20 records
Threat Entry Updated 2026-08-26

Dokan - Broken Access Control (CVE-2026-16576)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Managers to install and activate arbitrary Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 from WordPress.org.

PLUGIN Dokan

CVE-2026-16576

HIGH CVSS 7.2 2026-08-21
Threat Entry Updated 2026-08-26

Dokan - Security Vulnerability (CVE-2026-16575)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when category-based commission is configured, the per-category and default commission rates.

PLUGIN Dokan

CVE-2026-16575

MEDIUM CVSS 5.3 2026-08-21
Threat Entry Updated 2026-08-26

Dokan - Improper Input Validation (CVE-2026-16577)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.

PLUGIN Dokan

CVE-2026-16577

LOW CVSS 2.7 2026-08-21
Threat Entry Updated 2026-08-26

Dokan - Security Vulnerability (CVE-2026-16574)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.

PLUGIN Dokan

CVE-2026-16574

MEDIUM CVSS 5.4 2026-08-08
Threat Entry Updated 2026-08-12

Dokan - Privilege Escalation (CVE-2026-8761)

The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the `/dokan/v1/customers/` namespace and replaces WooCommerce's native `manage_woocommerce` capability check with a vendor-only check that inspects the **requesting** user's role and never validates the **target** user. This makes it possible for authenticated attackers with Vendor/Seller-level access and above to read, modify, or delete any WordPress user — including administrators — via…

PLUGIN Dokan

CVE-2026-8761

HIGH CVSS 8.8 2026-08-05
Threat Entry Updated 2026-08-26

Dokan - Security Vulnerability (CVE-2026-16565)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.

PLUGIN Dokan

CVE-2026-16565

MEDIUM CVSS 4.3 2026-08-03
Threat Entry Updated 2026-08-26

Dokan - Broken Access Control (CVE-2026-16564)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.

PLUGIN Dokan

CVE-2026-16564

MEDIUM CVSS 4.3 2026-08-03
Threat Entry Updated 2026-06-29

Dokan - Cross-Site Scripting (XSS) (CVE-2026-11783)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The malicious payload is delivered to site visitors — including unauthenticated users — when the store search widget…

PLUGIN Dokan

CVE-2026-11783

MEDIUM CVSS 6.4 2026-06-27
Threat Entry Updated 2026-06-29

Dokan - Security Vulnerability (CVE-2026-11987)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to read any other vendor's products — including unpublished draft and pending listings — exposing product names, prices, SKUs, and descriptions belonging to other vendors. The permission callbacks for both the collection…

PLUGIN Dokan

CVE-2026-11987

MEDIUM CVSS 4.3 2026-06-27
Threat Entry Updated 2026-06-18

Dokan - Security Vulnerability (CVE-2026-10023)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note, add_shipping_tracking_info, grant_access_to_download, and revoke_access_to_download AJAX handlers due to missing ownership validation on a user-controlled order ID key. This makes it possible for authenticated attackers, with custom vendor-level access and above, to modify the status of arbitrary orders, add attacker-controlled notes to any order (including customer-facing notes that trigger WooCommerce notification emails to…

PLUGIN Dokan

CVE-2026-10023

MEDIUM CVSS 4.3 2026-06-18
Threat Entry Updated 2026-06-17

Dokan - Information Disclosure (CVE-2026-3504)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due to the 'prepare_reviews_for_response' method including reviewer email addresses, usernames, and user IDs in the API response. This makes it possible for unauthenticated attackers to extract email addresses, usernames, and user IDs of all customers who left reviews on any vendor's store. The Pro version of the plugin must be installed and activated, with store reviews enabled,…

PLUGIN Dokan

CVE-2026-3504

MEDIUM CVSS 5.3 2026-05-02
Threat Entry Updated 2026-06-17

Dokan - Security Vulnerability (CVE-2025-14977)

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to missing validation on a user-controlled key. This makes it possible for authenticated attackers, with customer-level permissions and above, to read or modify other vendors' store settings including sensitive payment information (PayPal email, bank account details, routing numbers, IBAN, SWIFT codes), phone numbers, and addresses, and change PayPal email addresses to…

PLUGIN Dokan

CVE-2025-14977

HIGH CVSS 8.1 2026-01-20
Threat Entry Updated 2026-06-17

Dokan - SQL Injection (CVE-2024-3922)

The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Dokan

CVE-2024-3922

CRITICAL CVSS 10.0 2024-06-13
Threat Entry Updated 2026-06-17

Dokan - SQL Injection (CVE-2023-26525)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.12.

PLUGIN Dokan

CVE-2023-26525

HIGH CVSS 7.1 2023-12-20
Threat Entry Updated 2026-06-17

Dokan - PHP Object Injection (CVE-2023-34382)

Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.19.

PLUGIN Dokan

CVE-2023-34382

MEDIUM CVSS 4.4 2023-12-19
Threat Entry Updated 2026-06-17

Dokan - Cross-Site Request Forgery (CSRF) (CVE-2020-36748)

The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers to trigger an order export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Dokan

CVE-2020-36748

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-06-17

Dokan - SQL Injection (CVE-2022-3915)

The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

PLUGIN Dokan

CVE-2022-3915

CRITICAL CVSS 9.8 2022-12-12