Impact
The vulnerability is a PHP Object Injection flaw located in the subscriber handling code of the Dokan Pro plugin. An attacker can manipulate the plugin to instantiate arbitrary PHP objects, which may result in arbitrary code execution. The weakness is identified as CWE-502.
Affected Systems
Any WordPress site that has the Dokan Pro plugin version 5.0.2 or earlier installed is impacted. The plugin is provided by the vendor Dokan under the product name Dokan Pro. Sites that have not upgraded to 5.0.3 or later remain vulnerable unless the plugin has been removed or its subscriber functionality disabled.
Risk and Exploitability
CVSS score of 7.5 indicates a high severity. EPSS <1% suggests that exploitation in the wild is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be remote, via a crafted HTTP request that passes through Dokan Pro’s subscriber logic. Authentication is not explicitly required in the description, so the plugin could potentially be abused by unauthenticated users, but concrete prerequisites are not detailed.
OpenCVE Enrichment