Vulnerabilities and security researches fordokan-lite dokan-lite
Direction: ascendingJun 07, 2024
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2022-3915
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 12, 2022
- Research Description
- The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
- Affected versions
-
max 3.7.6.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2020-36748
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 01, 2023
- Research Description
- The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers to trigger an order export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 3.0.9.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2023-34382
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 20, 2023
- Research Description
- Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.19.
- Affected versions
-
max 3.7.20.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2022-3194
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 16, 2024
- Research Description
- The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.
- Affected versions
-
max 3.6.6.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # bb2edab103d44b4649118b1f5c0304ff9cfa61cf
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 01, 2021
- Research Description
- Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.2.1 WordPress Dokan plugin <= 3.2.0 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability found by NintechNet in WordPress Dokan plugin (versions <= 3.2.0).
- Affected versions
-
max 3.2.1.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2023-26525
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 20, 2023
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.12.
- Affected versions
-
max 3.7.13.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2021-4342
- CVE, Research URL
-
-
- Home page URL
- Application
- Date
- Jun 07, 2023
- Research Description
- Rejected reason: CVE split into individual CVE IDs for each software record.
- Affected versions
-
max 3.2.1.
- Status
-
vulnerable
Nov 10, 2025
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2025-53425
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 22, 2025
- Research Description
- Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <= 4.1.3.
- Affected versions
-
max 4.1.4.
- Status
-
vulnerable
Jan 28, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2025-14977
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 20, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to missing validation on a user-controlled key. This makes it possible for authenticated attackers, with customer-level permissions and above, to read or modify other vendors' store settings including sensitive payment information (PayPal email, bank account details, routing numbers, IBAN, SWIFT codes), phone numbers, and addresses, and change PayPal email addresses to attacker-controlled addresses, enabling financial theft when the marketplace processes payouts.
- Affected versions
-
max 4.2.5.
- Status
-
vulnerable
Apr 13, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-24359
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 25, 2026
- Research Description
- Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4.
- Affected versions
-
max 4.2.5.
- Status
-
vulnerable
May 03, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-3504
- CVE, Research URL
- Home page URL
- Application
- Date
- May 02, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due to the 'prepare_reviews_for_response' method including reviewer email addresses, usernames, and user IDs in the API response. This makes it possible for unauthenticated attackers to extract email addresses, usernames, and user IDs of all customers who left reviews on any vendor's store. The Pro version of the plugin must be installed and activated, with store reviews enabled, in order to exploit the vulnerability.
- Affected versions
-
max 4.3.2.
- Status
-
vulnerable
Jun 07, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-49780
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 16, 2026
- Research Description
- Customer Privilege Escalation in Dokan <= 5.0.2 versions.
- Affected versions
-
max 5.0.3.
- Status
-
vulnerable
Jun 16, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # d7d8cdd2103d6ed66c47ab59916b6b5509855016
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 07, 2023
- Research Description
- Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.20 Dokan <=3.7.19 - Authenticated(Shop Manager+) PHP Object Injection via create_dummy_vendor The Dokan plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7.19 via deserialization of untrusted input via the 'create_dummy_vendor' function called by the 'import' REST API endpoint. This allows authenticated attackers with Shop Manager privileges or above to inject a PHP Object. No POP chain is known to be present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
- Affected versions
-
max 3.7.20.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # 6e4c4a4bfec4dd43898361f2da9bca0322ce2b63
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 16, 2020
- Research Description
- Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.0.9 WordPress Dokan plugin <= 3.0.8 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Dokan plugin (versions <= 3.0.8).
- Affected versions
-
max 3.0.9.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # e03420c55099714ac90da016761d318e5e1cb6db
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.2.1 404 Page Not Found
- Affected versions
-
max 3.2.1.
- Status
-
vulnerable
Jun 19, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-10023
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 18, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note, add_shipping_tracking_info, grant_access_to_download, and revoke_access_to_download AJAX handlers due to missing ownership validation on a user-controlled order ID key. This makes it possible for authenticated attackers, with custom vendor-level access and above, to modify the status of arbitrary orders, add attacker-controlled notes to any order (including customer-facing notes that trigger WooCommerce notification emails to buyers), delete any order note or WordPress comment by ID regardless of ownership, inject fake shipping tracking information on any order, and grant or revoke downloadable-product permissions on any order in the marketplace. Critically, nonce validity is not a barrier to exploitation: each of these AJAX handlers generates and embeds its nonce on the authenticated vendor's own dashboard order pages (e.g., /dashboard/orders/?order_id=OWN_ORDER_ID), which the attacker legitimately controls. The attacker harvests a valid nonce from their own order detail page and replays it against a victim order ID — the nonce only proves the request originates from a logged-in session, not that the order belongs to that vendor. This directly rebuts the prior rejection reasoning that 'users cannot generate valid nonces on command': vendor users can and do generate valid nonces on demand simply by loading their own dashboard pages. Source-code analysis confirmed the vulnerable code path is present and unpatched through version 5.0.1.
- Affected versions
-
max 5.0.4.
- Status
-
vulnerable
Jun 30, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-11987
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 27, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to read any other vendor's products — including unpublished draft and pending listings — exposing product names, prices, SKUs, and descriptions belonging to other vendors. The permission callbacks for both the collection endpoint and the single-item endpoint only verify the generic vendor capability ('dokan_view_product_menu' / 'dokandar'), which every vendor holds, rather than confirming the requested author ID or product ownership matches the authenticated user.
- Affected versions
-
max 5.0.5.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-11783
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 27, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The malicious payload is delivered to site visitors — including unauthenticated users — when the store search widget inserts the unescaped AJAX response HTML into the DOM via jQuery's .html() method.
- Affected versions
-
max 5.0.5.
- Status
-
vulnerable
Jul 15, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-57706
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 13, 2026
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6.
- Affected versions
-
max 5.0.7.
- Status
-
vulnerable
Aug 05, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-16564
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 03, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.
- Affected versions
-
max 5.0.9.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-16565
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 03, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
- Affected versions
-
max 5.0.9.
- Status
-
vulnerable
Aug 11, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-16574
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 08, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.
- Affected versions
-
max 5.0.11.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-66699
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 06, 2026
- Research Description
- Custom role Broken Access Control in Dokan <= 5.0.10 versions.
- Affected versions
-
max 5.0.11.
- Status
-
vulnerable
Aug 22, 2026
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-16575
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 21, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when category-based commission is configured, the per-category and default commission rates.
- Affected versions
-
max 5.0.14.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-16577
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 21, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.
- Affected versions
-
max 5.0.14.
- Status
-
vulnerable
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy # CVE-2026-16576
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 21, 2026
- Research Description
- The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Managers to install and activate arbitrary Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 from WordPress.org.
- Affected versions
-
max 5.0.14.
- Status
-
vulnerable