Dokan

Dokan

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 20.01.2026 04:35:45
  • Zuletzt bearbeitet 26.01.2026 15:05:23

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings`...

  • EPSS 0.07%
  • Veröffentlicht 22.10.2025 14:32:33
  • Zuletzt bearbeitet 20.01.2026 15:16:54

Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <= 4.1.2.

  • EPSS 88.5%
  • Veröffentlicht 13.06.2024 02:15:08
  • Zuletzt bearbeitet 25.02.2026 15:10:10

The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 16.01.2024 16:15:09
  • Zuletzt bearbeitet 24.02.2026 20:58:39

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.

  • EPSS 0.13%
  • Veröffentlicht 20.12.2023 18:15:11
  • Zuletzt bearbeitet 24.02.2026 20:57:36

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Mul...

  • EPSS 0.15%
  • Veröffentlicht 19.12.2023 20:15:07
  • Zuletzt bearbeitet 24.02.2026 20:59:24

Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amaz...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 01.07.2023 06:15:09
  • Zuletzt bearbeitet 24.02.2026 20:59:03

The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated...

Exploit
  • EPSS 3.25%
  • Veröffentlicht 12.12.2022 18:15:11
  • Zuletzt bearbeitet 24.02.2026 20:58:05

The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users