Description
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Managers to install and activate arbitrary Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 from WordPress.org.
Published: 2026-08-21
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Dokan "AI Powered WooCommerce Multivendor Marketplace Solution" plugin for WordPress fails to verify the precise user capability on several admin REST API routes. Rather than checking the dedicated Dokan installation capability, the system only verifies a generic WooCommerce management right. This oversight permits users with the Shop Manager role to issue a REST request that instructs WordPress to download and activate any plugin from WordPress.org. An attacker can therefore inject a malicious plugin that may contain backdoors, exfiltration code, or additional exploits. The flaw constitutes a privilege escalation that ultimately enables arbitrary code execution and significant loss of integrity and confidentiality for the affected WordPress installation.

Affected Systems

WordPress sites that have the Dokan "AI Powered WooCommerce Multivendor Marketplace Solution" plugin installed at any version prior to 5.0.14 and where a Shop Manager (or a similar role with WooCommerce management capability) exists. All sites that have not applied the 5.0.14 or later update are exposed, regardless of other security controls.

Risk and Exploitability

While the CVSS score is not provided and the EPSS is unavailable, the vulnerability allows authenticated attackers to exploit a REST endpoint that is publicly accessible to a user with sufficient privileges. The required effort is low if a Shop Manager account is present, and the impact is high, enabling arbitrary plugin installation and execution. No KEV listing or known exploitation references are reported, but the attack vector is clear and the consequence severe. The immediate risk therefore lies in the combination of privilege escalation and the ability to execute arbitrary code on the host.

Generated by OpenCVE AI on August 21, 2026 at 08:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Dokan plugin to version 5.0.14 or later, which corrects the capability check on the REST API routes.
  • Revise role capabilities by removing the WooCommerce management right from the Shop Manager role or by creating a custom role that restricts plugin installation privileges.
  • Block or restrict access to the REST API endpoints that enable plugin installation, for example by firewall rules or by disabling the REST API for unauthenticated traffic.

Generated by OpenCVE AI on August 21, 2026 at 08:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress
Vendors & Products Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress

Fri, 21 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Managers to install and activate arbitrary Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 from WordPress.org.
Title Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API
References

Subscriptions

Dokan Ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-21T06:00:16.453Z

Reserved: 2026-07-22T13:01:59.329Z

Link: CVE-2026-16576

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T07:16:24.740

Modified: 2026-08-21T07:16:24.740

Link: CVE-2026-16576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T08:15:03Z

Weaknesses

No weakness.