CVE-2026-66699
- EPSS 0.18%
- Veröffentlicht 06.08.2026 14:28:04
- Zuletzt bearbeitet 12.08.2026 20:58:37
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
CVE-2026-8761
- EPSS 0.37%
- Veröffentlicht 05.08.2026 04:25:24
- Zuletzt bearbeitet 12.08.2026 21:00:37
The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), whi...
CVE-2026-65495
- EPSS 0.3%
- Veröffentlicht 23.07.2026 11:19:01
- Zuletzt bearbeitet 23.07.2026 14:17:54
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
CVE-2026-57706
- EPSS 0.18%
- Veröffentlicht 13.07.2026 08:41:24
- Zuletzt bearbeitet 13.07.2026 16:57:56
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6.
CVE-2026-11783
- EPSS 0.24%
- Veröffentlicht 27.06.2026 06:50:56
- Zuletzt bearbeitet 29.06.2026 18:40:23
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient i...
CVE-2026-11987
- EPSS 0.27%
- Veröffentlicht 27.06.2026 06:50:55
- Zuletzt bearbeitet 29.06.2026 20:17:32
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to mi...
CVE-2026-10023
- EPSS 0.24%
- Veröffentlicht 18.06.2026 03:41:38
- Zuletzt bearbeitet 18.06.2026 03:41:38
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add...
CVE-2026-49780
- EPSS 0.28%
- Veröffentlicht 15.06.2026 20:19:28
- Zuletzt bearbeitet 15.06.2026 21:24:32
Customer Privilege Escalation in Dokan <= 5.0.2 versions.
CVE-2026-3504
- EPSS 0.26%
- Veröffentlicht 02.05.2026 13:26:09
- Zuletzt bearbeitet 05.05.2026 19:15:06
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due...
CVE-2026-24359
- EPSS 0.52%
- Veröffentlicht 25.03.2026 16:14:31
- Zuletzt bearbeitet 24.04.2026 16:32:53
Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4.