Skip to content
Noroxi

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

dokan-lite · plugin

Known security vulnerabilities for Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy. Find out in seconds which version runs on your site with WP Lens.

14 known vulnerabilities

5 exploitable without logging in · latest Aug 6, 2026

Listed on wordpress.org · latest 5.2.1 · last updated Sep 30, 2026 · 30K+ installs

wordpress.org status checked on Oct 5, 2026

Vulnerabilities

  • CVE-2026-8761login required

    Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation

    High 8.8
  • CVE-2026-49780customer+≤ 5.0.2

    WordPress Dokan plugin <= 5.0.2 - Privilege Escalation vulnerability

    High 8.8
  • CVE-2026-24359login required≤ 4.2.4

    WordPress Dokan plugin <= 4.2.4 - Broken Authentication vulnerability

    High 8.8
  • CVE-2023-34382high privilege≤ 3.7.19

    WordPress Dokan Plugin <= 3.7.19 is vulnerable to PHP Object Injection

    High 8.8
  • CVE-2025-14977customer+≤ 4.2.4

    Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account

    High 8.1
  • CVE-2023-26525login required≤ 3.7.12

    WordPress Dokan Plugin <= 3.7.12 is vulnerable to SQL Injection

    High 8.1
  • CVE-2025-53425high privilege≤ 4.1.3

    WordPress Dokan plugin <= 4.1.3 - Privilege Escalation vulnerability

    High 7.2
  • CVE-2026-57706unauthenticated · needs a click≤ 5.0.6

    WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-11783unauthenticated≤ 5.0.4

    Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU

    Medium 6.4
  • CVE-2026-66699unauthenticated≤ 5.0.10

    WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2026-3504unauthenticated≤ 4.3.1

    Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API Endpoint

    Medium 5.3
  • CVE-2020-36748unauthenticated · needs a click→ 3.0.9

    Dokan <= 3.0.8 - Cross-Site Request Forgery Bypass

    Medium 4.3
  • CVE-2026-11987subscriber+≤ 5.0.4

    Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure

    Medium 4.3
  • CVE-2026-10023login required≤ 5.0.3

    Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modificati

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory