Description
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
Published: 2026-07-23
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability is an unauthenticated broken access control flaw in Dokan Pro plugin versions up to 5.0.3. An attacker can perform privileged operations normally reserved for vendor or administrator users without authenticating. This could allow the creation or modification of listings, alteration of orders, and access to sensitive customer data. The weakness is classified as CWE‑862 and can compromise confidentiality and integrity for all site users.

Affected Systems

Affected products are Dokan Multivendor Plugin – Dokan Pro 5.0.3 and earlier. The flaw exists in all releases of Dokan Pro up to and including 5.0.3. No other vendors or versions are mentioned. Websites running an unpatched version of Dokan Pro are vulnerable.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity, while the EPSS score is below 1 percent, suggesting the likelihood of exploitation is relatively low at this time. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers would need to send crafted HTTP requests to the plugin’s endpoints, and because the flaw is unauthenticated, no prior credential is required. The likely attack vector is a direct, unauthenticated HTTP request, and the risk is therefore high for sites relying on Dokan Pro and moderate in terms of exploit probability.

Generated by OpenCVE AI on August 4, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dokan Pro to version 5.0.4 or later to obtain the fix for the broken access control issue.
  • Restrict vendor and admin capabilities to legitimate roles only and remove any unnecessary permissions from default user roles.
  • Enable logging and regularly review access logs for unusual or unauthorized activity that may exploit the access control flaw.

Generated by OpenCVE AI on August 4, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Dokan Multivendor Plugin
Dokan Multivendor Plugin dokan Pro
Wordpress
Wordpress wordpress
Vendors & Products Dokan Multivendor Plugin
Dokan Multivendor Plugin dokan Pro
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
Title WordPress Dokan Pro plugin <= 5.0.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Dokan Multivendor Plugin Dokan Pro
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:41:55.388Z

Reserved: 2026-07-22T08:53:43.312Z

Link: CVE-2026-65495

cve-icon Vulnrichment

Updated: 2026-07-23T13:41:50.993Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:42.790

Modified: 2026-07-23T14:17:54.020

Link: CVE-2026-65495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses