Impact
Dokan versions preceding 5.0.14 expose per‑vendor commission settings through a REST endpoint that does not require authentication. An attacker can retrieve the vendor’s commission type and, when category‑based commissions are enabled, the exact rates for each category and the default rate. This constitutes a direct breach of confidentiality, but does not allow code execution, privilege escalation, or service disruption.
Affected Systems
WordPress sites that run the Dokan AI Powered WooCommerce Multivendor Marketplace plugin at any version older than 5.0.14 are vulnerable. The flaw applies universally to all such installations, regardless of other WordPress configuration or host security settings.
Risk and Exploitability
Exploitation is straightforward: an unauthenticated HTTP GET to the store categories REST endpoint returns sensitive commission data because the plugin performs no access control checks. No exploit code has been reported and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet triggered widespread attacks. Nevertheless, the confidentiality loss is significant, and the low barrier to exploitation makes it attractive to adversaries.
OpenCVE Enrichment