Description
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when category-based commission is configured, the per-category and default commission rates.
Published: 2026-08-21
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dokan versions preceding 5.0.14 expose per‑vendor commission settings through a REST endpoint that does not require authentication. An attacker can retrieve the vendor’s commission type and, when category‑based commissions are enabled, the exact rates for each category and the default rate. This constitutes a direct breach of confidentiality, but does not allow code execution, privilege escalation, or service disruption.

Affected Systems

WordPress sites that run the Dokan AI Powered WooCommerce Multivendor Marketplace plugin at any version older than 5.0.14 are vulnerable. The flaw applies universally to all such installations, regardless of other WordPress configuration or host security settings.

Risk and Exploitability

Exploitation is straightforward: an unauthenticated HTTP GET to the store categories REST endpoint returns sensitive commission data because the plugin performs no access control checks. No exploit code has been reported and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet triggered widespread attacks. Nevertheless, the confidentiality loss is significant, and the low barrier to exploitation makes it attractive to adversaries.

Generated by OpenCVE AI on August 21, 2026 at 08:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Dokan 5.0.14 or later, which eliminates unauthenticated access to commission settings.
  • If upgrading is delayed, restrict the Dokan REST API by configuring the web server or firewall to allow only authenticated or authorized IP ranges.
  • Monitor REST API traffic and audit access logs for unexpected requests to detect potential unauthorized data disclosure.

Generated by OpenCVE AI on August 21, 2026 at 08:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Fri, 21 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress
Vendors & Products Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress

Fri, 21 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when category-based commission is configured, the per-category and default commission rates.
Title Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint
References

Subscriptions

Dokan Ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-21T06:00:16.279Z

Reserved: 2026-07-22T13:01:27.663Z

Link: CVE-2026-16575

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T07:16:24.637

Modified: 2026-08-21T07:16:24.637

Link: CVE-2026-16575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T08:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor