Description
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.
Published: 2026-08-21
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Dokan plugin before version 5.0.14 records reverse‑withdrawal payments without checking the amount against the vendor’s actual outstanding balance. This flaw lets a vendor credit their reverse‑withdrawal ledger with any arbitrary amount, effectively wiping out commission debt without providing payment. The consequence is financial fraud against the platform, compromising the integrity of vendor settlements. This deficit results from improper validation of client‑supplied data—an access control failure reflected in CWE‑285 and a failure to enforce input constraints reflected in CWE‑398.

Affected Systems

The vulnerability affects any installation of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution on WordPress that uses a version prior to 5.0.14. No specific build numbers are listed beyond the major release cutoff.

Risk and Exploitability

Because the flaw is triggered by client‑supplied data within an already trusted vendor context, a malicious vendor can exploit it immediately without needing code execution or remote access. The EPSS score is unavailable and the vulnerability is not listed in CISA KEV, but the financial impact is high. The CVSS score is not provided, yet the risk remains significant for platforms relying on Dokan for commission settlement.

Generated by OpenCVE AI on August 21, 2026 at 08:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Dokan v5.0.14 or later to receive proper validation of reverse‑withdrawal amounts
  • If an upgrade is not yet possible, disable the reverse‑withdrawal functionality for all vendors until the patch is applied
  • Conduct a manual audit of vendor ledger entries and reconcile any discrepancies caused by the vulnerability

Generated by OpenCVE AI on August 21, 2026 at 08:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-398

Fri, 21 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress
Vendors & Products Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress

Fri, 21 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.
Title Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount
References

Subscriptions

Dokan Ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-21T06:00:16.623Z

Reserved: 2026-07-22T13:03:19.390Z

Link: CVE-2026-16577

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T07:16:24.840

Modified: 2026-08-21T07:16:24.840

Link: CVE-2026-16577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T08:15:03Z

Weaknesses