Impact
Unauthenticated Cross Site Scripting (XSS) is present in Dokan Pro versions up to 5.0.0. This flaw allows an attacker to inject arbitrary client‑side code into a page viewed by any visitor. The vulnerability can be triggered without login and enables phishing, session cookie theft, and execution of malicious actions within the user’s browser context, as classified by CWE‑79.
Affected Systems
WordPress sites that have the Dokan Pro plugin version 5.0.0 or earlier are affected. The plugin replaces vulnerable code paths with proper sanitization in all releases newer than 5.0.0.
Risk and Exploitability
The CVSS base score of 7.1 reflects moderate‑to‑high severity. An EPSS of less than 1% indicates a low probability of widespread exploitation, and the vulnerability is not listed in CISA's KEV catalog. Attackers can craft a malicious URL or submit malicious data via a publicly exposed form to trigger the XSS; no authentication or privileged access is required.
OpenCVE Enrichment