Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
dokan-lite · plugin
Known security vulnerabilities for Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy. Find out in seconds which version runs on your site with WP Lens.
14 known vulnerabilities
5 exploitable without logging in · latest Aug 6, 2026
Listed on wordpress.org · latest 5.2.1 · last updated Sep 30, 2026 · 30K+ installs
wordpress.org status checked on Oct 5, 2026
Vulnerabilities
- High 8.8
CVE-2026-8761login required
Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation
- High 8.8
CVE-2026-49780customer+≤ 5.0.2
WordPress Dokan plugin <= 5.0.2 - Privilege Escalation vulnerability
- High 8.8
CVE-2026-24359login required≤ 4.2.4
WordPress Dokan plugin <= 4.2.4 - Broken Authentication vulnerability
- High 8.8
CVE-2023-34382high privilege≤ 3.7.19
WordPress Dokan Plugin <= 3.7.19 is vulnerable to PHP Object Injection
- High 8.1
CVE-2025-14977customer+≤ 4.2.4
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account
- High 8.1
CVE-2023-26525login required≤ 3.7.12
WordPress Dokan Plugin <= 3.7.12 is vulnerable to SQL Injection
- High 7.2
CVE-2025-53425high privilege≤ 4.1.3
WordPress Dokan plugin <= 4.1.3 - Privilege Escalation vulnerability
- High 7.1
CVE-2026-57706unauthenticated · needs a click≤ 5.0.6
WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability
- Medium 6.4
CVE-2026-11783unauthenticated≤ 5.0.4
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU
- Medium 5.3
CVE-2026-66699unauthenticated≤ 5.0.10
WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability
- Medium 5.3
CVE-2026-3504unauthenticated≤ 4.3.1
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API Endpoint
- Medium 4.3
CVE-2020-36748unauthenticated · needs a click→ 3.0.9
Dokan <= 3.0.8 - Cross-Site Request Forgery Bypass
- Medium 4.3
CVE-2026-11987subscriber+≤ 5.0.4
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure
- Medium 4.3
CVE-2026-10023login required≤ 5.0.3
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modificati
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).