CVE-2026-24359
- EPSS 0.06%
- Veröffentlicht 25.03.2026 16:14:31
- Zuletzt bearbeitet 30.03.2026 13:27:35
Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4.
CVE-2025-14977
- EPSS 0.04%
- Veröffentlicht 20.01.2026 04:35:45
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings`...
CVE-2025-53425
- EPSS 0.08%
- Veröffentlicht 22.10.2025 14:32:33
- Zuletzt bearbeitet 15.04.2026 00:35:42
Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <= 4.1.3.
CVE-2024-3922
- EPSS 89.48%
- Veröffentlicht 13.06.2024 02:15:08
- Zuletzt bearbeitet 08.04.2026 19:21:29
The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...
CVE-2022-3194
- EPSS 0.26%
- Veröffentlicht 16.01.2024 16:15:09
- Zuletzt bearbeitet 24.02.2026 20:58:39
The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.
CVE-2023-26525
- EPSS 0.14%
- Veröffentlicht 20.12.2023 18:15:11
- Zuletzt bearbeitet 24.02.2026 20:57:36
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Mul...
CVE-2023-34382
- EPSS 0.15%
- Veröffentlicht 19.12.2023 20:15:07
- Zuletzt bearbeitet 24.02.2026 20:59:24
Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amaz...
CVE-2020-36748
- EPSS 0.12%
- Veröffentlicht 01.07.2023 06:15:09
- Zuletzt bearbeitet 08.04.2026 18:17:11
The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated...
CVE-2022-3915
- EPSS 3.25%
- Veröffentlicht 12.12.2022 18:15:11
- Zuletzt bearbeitet 24.02.2026 20:58:05
The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users