Impact
The Dokan WordPress plugin does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through its order REST endpoint. This allows an authenticated vendor to give their own customers free download access to another vendor’s paid downloadable files, exposing paid content and reducing revenue.
Affected Systems
Affected product is the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin, version 5.0.10 and earlier. Any site running a version before 5.0.11 is vulnerable.
Risk and Exploitability
The vulnerability can be exploited by any vendor with legitimate access to the plugin’s REST API. Though it does not provide code execution, it permits the unapproved distribution of paid content. No EPSS score is available and it is not listed in CISA KEV, but the impact on confidentiality, integrity, and financial loss suggests a high risk. The attack vector is the order download endpoint and requires only authenticated vendor credentials.
OpenCVE Enrichment