Description
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.
Published: 2026-08-21
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized ledger manipulation that allows a vendor to clear commission debt without payment
Action: Patch Immediately
AI Analysis

Impact

The Dokan plugin before version 5.0.14 accepts vendor‑supplied amounts for reverse‑withdrawal payments without validating them against the vendor’s true outstanding balance. Because the input is unchecked, a malicious vendor can credit their ledger with an arbitrary amount, effectively erasing commission debt without making any real payment. This flaw is an example of missing authorization checks (CWE‑863). The result is financial fraud against the platform, compromising the integrity of vendor settlements.

Affected Systems

The vulnerability affects any WordPress site that installs the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin on a version earlier than 5.0.14. No additional build or patch levels are listed beyond this release cutoff, so all deployments of Dokan prior to 5.0.14 are potentially impacted.

Risk and Exploitability

The CVSS score of 2.7 indicates low base severity, and the EPSS score of < 1% suggests a very low likelihood of mass exploitation. The flaw does not require code execution and can be triggered by any vendor who can submit a reverse‑withdrawal request, so the attack vector is local to the vendor’s own account. Although not listed in CISA’s KEV catalog, the financial damage that could result from abused ledger entries justifies an urgent patch.

Generated by OpenCVE AI on August 21, 2026 at 17:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Dokan v5.0.14 or later to enforce proper validation of reverse withdrawal amounts
  • If an upgrade cannot be performed immediately, disable reverse withdrawal functionality for all vendors until the patch is applied
  • Perform a manual audit of vendor ledger entries to detect and correct any fraudulent adjustments caused by the vulnerability

Generated by OpenCVE AI on August 21, 2026 at 17:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-398

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-398

Fri, 21 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress
Vendors & Products Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress

Fri, 21 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.
Title Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount
References

Subscriptions

Dokan Ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-21T12:54:06.551Z

Reserved: 2026-07-22T13:03:19.390Z

Link: CVE-2026-16577

cve-icon Vulnrichment

Updated: 2026-08-21T12:52:57.780Z

cve-icon NVD

Status : Deferred

Published: 2026-08-21T07:16:24.840

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-16577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:45:03Z

Weaknesses