← WordPress Vulnerabilities
WordPress security by component

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution adds multivendor marketplace functionality to WooCommerce, allowing multiple sellers to manage products and orders.

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution (dokan-ai-powered-woocommerce-multivendor-marketplace-solution) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 4.3.

Plugin slug: dokan-ai-powered-woocommerce-multivendor-marketplace-solution

CVE-2026-16565: Dokan vendors can modify other vendors' product attributes

Dokan before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints. A user with a Dokan vendor account can submit another vendor's product identifier and change that product's attributes and default attributes. The CNA record does not disclose the REST routes, request fields, callbacks or affected attribute values.

PublishedAug 03, 2026
Known safe version5.0.9
Published vulnerabilities for dokan-ai-powered-woocommerce-multivendor-marketplace-solution
Safe version
Aug 03, 2026 CVE-2026-16565
Dokan vendors can modify other vendors' product attributes
Dokan before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints. A user with a Dokan vendor account can submit another vendor's product identifier and change that product's attributes and default attributes. The CNA record does not disclose the REST routes, request fields, callbacks or affected attribute values.
5.0.9
CVE4.3
NVDPending
Aug 03, 2026 CVE-2026-16564
Dokan vendors can change the status of any marketplace order
Dokan before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes. A user with a Dokan vendor account can supply orders belonging to other vendors or the store's customers and change their status. The CNA record does not disclose the route, order-ID field, status field or callback.
5.0.9
CVE4.3
NVDPending