Impact
The Dokan plugin before version 5.0.14 accepts vendor‑supplied amounts for reverse‑withdrawal payments without validating them against the vendor’s true outstanding balance. Because the input is unchecked, a malicious vendor can credit their ledger with an arbitrary amount, effectively erasing commission debt without making any real payment. This flaw is an example of missing authorization checks (CWE‑863). The result is financial fraud against the platform, compromising the integrity of vendor settlements.
Affected Systems
The vulnerability affects any WordPress site that installs the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin on a version earlier than 5.0.14. No additional build or patch levels are listed beyond this release cutoff, so all deployments of Dokan prior to 5.0.14 are potentially impacted.
Risk and Exploitability
The CVSS score of 2.7 indicates low base severity, and the EPSS score of < 1% suggests a very low likelihood of mass exploitation. The flaw does not require code execution and can be triggered by any vendor who can submit a reverse‑withdrawal request, so the attack vector is local to the vendor’s own account. Although not listed in CISA’s KEV catalog, the financial damage that could result from abused ledger entries justifies an urgent patch.
OpenCVE Enrichment