Description
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
Published: 2026-08-03
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Dokan AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin, in all releases prior to 5.0.9, allows a vendor to use its product-attribute REST write endpoints without verifying that the vendor owns the target product. This flaw enables a vendor to change the attributes and default attributes of any other vendor’s products, subtly or dramatically altering product listings, prices, or availability. The impact is a loss of data integrity and potential financial harm in a marketplace with multiple vendors, since unauthorized changes can affect earnings, reviews, and customer trust.

Affected Systems

Any WordPress site that has installed the Dokan plugin in a version earlier than 5.0.9 is directly affected. The vulnerability applies to all vendors of the marketplace who have standard vendor accounts providing access to the product-attribute REST API.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the flaw is exploitable through the publicly documented REST API once a vendor account has been created. An attacker would need only legitimate API credentials and the ability to target another vendor’s product ID. Because the vulnerability enables unauthorized write access, the risk to the integrity of the marketplace is high, and the CVSS score of 4.3 indicates a moderate severity. The attack vector is inferred to be remote, authenticated via the API, relying on the absence of ownership checks.

Generated by OpenCVE AI on August 4, 2026 at 22:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Dokan plugin to version 5.0.9 or later, where ownership verification is enforced on product-attribute write endpoints.
  • If an upgrade is not immediately possible, restrict vendor roles so that they cannot access product-attribute write endpoints, or disable those endpoints entirely via a security plugin or custom code.
  • Review all existing product attributes for unauthorized changes and reapply correct values, documenting any discrepancies found during the audit.

Generated by OpenCVE AI on August 4, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress
Vendors & Products Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress

Mon, 03 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
Title Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
References

Subscriptions

Dokan Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-03T17:30:41.066Z

Reserved: 2026-07-22T12:39:47.324Z

Link: CVE-2026-16565

cve-icon Vulnrichment

Updated: 2026-08-03T17:15:54.562Z

cve-icon NVD

Status : Received

Published: 2026-08-03T07:16:42.093

Modified: 2026-08-03T18:16:38.053

Link: CVE-2026-16565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:30:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key