Impact
The Dokan plugin for WordPress contains an improper neutralization of input during web page generation that allows a reflected cross‑site scripting flaw. Malicious content can be injected into a page and executed in the target's browser when a crafted request is processed. This permits the attacker to steal session cookies, deface the site, or deliver malware, but is confined to the victim’s browser and does not provide any server‑side execution.
Affected Systems
Dokan, Inc. Dokan plugin for WordPress, all versions5.0.6, including the dokan‑lite package, are vulnerable. Sites using the plugin should check the installed version and upgrade if 5.0.6 or SS score of 7.1 indicates a high‑severity vulnerability, yet the EPSS score of less than 1 % points to an extremely low likelihood of exploitation in the wild. Because the flaw is reflected XSS, the attacker must lure a victim to a specially crafted URL; there is no known exploitation in production or inclusion in the CISA KEV catalog. Nonetheless, sites that are public facing or host valuable assets should prepare to mitigate.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity within the context of a reflected XSS. However, an EPSS score of less than 1 % indicates that the likelihood of an attacker actively exploiting this flaw in the wild is currently very low. The vulnerability is not listed in the CISA KEV catalog, further supporting the low exploitation probability. Attackers can trigger the flaw by luring victims to a maliciously crafted URL that includes the reflected payload; no privileged access or additional vulnerabilities are required. If an attacker succeeds, the impact is limited to the victim’s browser and does not allow remote code execution or direct server compromise, but it can still compromise user credentials, session state, or perform defacement. Public‑facing WordPress sites that use Dokan should still prioritize remediation, as the availability of the flaw means attackers can create a convincing phishing link to exploit unsuspecting users.
OpenCVE Enrichment