HomeWordPress vulnerabilitiesDokan
Dokan vulnerabilities
Dokan has 9 known vulnerabilities in this database. The most recent published record is dated 5 Aug 2026.
- Known vulnerabilities
- 9
- Active installs
- 30,000+
- Latest version
- 5.2.1
- Last updated
- 30 Sep 2026
- Most recent
- 5 Aug 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Privilege escalation CVE-2026-8761 | High 8.8 | Up to 5.0.1 | Fixed in a later version (latest 5.2.1) | 5 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-11783 | Medium 6.4 | Up to 5.0.4 | Fixed in a later version (latest 5.2.1) | 27 Jun 2026 |
| Broken access control CVE-2026-11987 | Medium 4.3 | Up to 5.0.4 | Fixed in a later version (latest 5.2.1) | 27 Jun 2026 |
| Broken access control CVE-2026-10023 | Medium 4.3 | Up to 5.0.3 | Fixed in a later version (latest 5.2.1) | 18 Jun 2026 |
| Sensitive data exposure CVE-2026-3504 | Medium 5.3 | Up to 4.3.1 | Fixed in a later version (latest 5.2.1) | 2 May 2026 |
| Broken access control CVE-2025-14977 | High 8.1 | Up to 4.2.4 | Fixed in a later version (latest 5.2.1) | 20 Jan 2026 |
| Cross-site scripting (XSS) CVE-2022-3194 | Medium 5.4 | Before 3.6.4 | Fixed in 3.6.4 | 16 Jan 2024 |
| Cross-site request forgery (CSRF) CVE-2020-36748 | Medium 4.3 | Before 3.0.9 | Fixed in 3.0.9 | 1 Jul 2023 |
| SQL injection CVE-2022-3915 | Critical 9.8 | Before 3.7.6 | Fixed in 3.7.6 | 12 Dec 2022 |
Read the published descriptions
- CVE-2026-8761, 5 Aug 2026
- The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the `/dokan/v1/customers/` namespace and replaces WooCommerce's native `manage_woocommerce` capability check with a vendor-only check that inspects the **requesting** user's role and never validates the **target** user. This makes it possible for authenticated attackers with Vendor/Seller-level access and above to read, modify, or delete any WordPress user - including administrators - via `GET`/`PUT`/`DELETE` requests against `/wp-json/dokan/v1/customers/{id}`. Setting the `password` parameter on an administrator's record yields a full site takeover. CVE record
- CVE-2026-11783, 27 Jun 2026
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution - Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The malicious payload is delivered to site visitors - including unauthenticated users - when the store search widget inserts the unescaped AJAX response HTML into the DOM via jQuery's .html() method. CVE record
- CVE-2026-11987, 27 Jun 2026
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution - Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to read any other vendor's products - including unpublished draft and pending listings - exposing product names, prices, SKUs, and descriptions belonging to other vendors. The permission callbacks for both the collection endpoint and the single-item endpoint only verify the generic vendor capability ('dokan_view_product_menu' / 'dokandar'), which every vendor holds, rather than confirming the requested author ID or product ownership matches the authenticated user. CVE record
- CVE-2026-10023, 18 Jun 2026
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution - Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note, add_shipping_tracking_info, grant_access_to_download, and revoke_access_to_download AJAX handlers due to missing ownership validation on a user-controlled order ID key. This makes it possible for authenticated attackers, with custom vendor-level access and above, to modify the status of arbitrary orders, add attacker-controlled notes to any order (including customer-facing notes that trigger WooCommerce notification emails to buyers), delete any order note or WordPress comment by ID regardless of ownership, inject fake shipping tracking information on any order, and grant or revoke downloadable-product permissions on any order in the marketplace. Critically, nonce validity is not a barrier to exploitation: each of these AJAX handlers generates and embeds its nonce on the authenticated vendor's own dashboard order pages (e.g., /dashboard/orders/?order_id=OWN_ORDER_ID), which the attacker legitimately controls. The attacker harvests a valid nonce from their own order detail page and replays it against a victim order ID - the nonce only proves the request originates from a logged-in session, not that the order belongs to that vendor. This directly rebuts the prior rejection reasoning that 'users cannot generate valid nonces on command': vendor users can and do generate valid nonces on demand simply by loading their own dashboard pages. Source-code analysis confirmed the vulnerable code path is present and unpatched through version 5.0.1. CVE record
- CVE-2026-3504, 2 May 2026
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due to the 'prepare_reviews_for_response' method including reviewer email addresses, usernames, and user IDs in the API response. This makes it possible for unauthenticated attackers to extract email addresses, usernames, and user IDs of all customers who left reviews on any vendor's store. The Pro version of the plugin must be installed and activated, with store reviews enabled, in order to exploit the vulnerability. CVE record
- CVE-2025-14977, 20 Jan 2026
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution - Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to missing validation on a user-controlled key. This makes it possible for authenticated attackers, with customer-level permissions and above, to read or modify other vendors' store settings including sensitive payment information (PayPal email, bank account details, routing numbers, IBAN, SWIFT codes), phone numbers, and addresses, and change PayPal email addresses to attacker-controlled addresses, enabling financial theft when the marketplace processes payouts. CVE record
- CVE-2022-3194, 16 Jan 2024
- The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators. CVE record
- CVE-2020-36748, 1 Jul 2023
- The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers to trigger an order export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2022-3915, 12 Dec 2022
- The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users CVE record
What to do if you run Dokan
If you run Dokan, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Dokan vulnerabilities
Free. We email you when a new vulnerability is published for Dokan, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.