Impact
Based on the description, it is inferred that the vulnerability is an unauthenticated broken access control flaw in Dokan Pro plugin versions up to 5.0.3. An attacker can perform privileged operations normally reserved for vendor or administrator users without authenticating. This could allow the creation or modification of listings, alteration of orders, and access to sensitive customer data. The weakness is classified as CWE‑862 and can compromise confidentiality and integrity for all site users.
Affected Systems
Affected products are Dokan Multivendor Plugin – Dokan Pro 5.0.3 and earlier. The flaw exists in all releases of Dokan Pro up to and including 5.0.3. No other vendors or versions are mentioned. Websites running an unpatched version of Dokan Pro are vulnerable.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity, while the EPSS score is below 1 percent, suggesting the likelihood of exploitation is relatively low at this time. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers would need to send crafted HTTP requests to the plugin’s endpoints, and because the flaw is unauthenticated, no prior credential is required. The likely attack vector is a direct, unauthenticated HTTP request, and the risk is therefore high for sites relying on Dokan Pro and moderate in terms of exploit probability.
OpenCVE Enrichment