Impact
Custom role Broken Access Control in Dokan versions up to 5.0.10 enables an attacker to execute operations restricted to higher-privilege roles, thereby granting unauthorized access to sensitive administrative functions. The vulnerability stems from inadequate enforcement of role checks before performing protected actions, allowing privilege escalation by users with lower permissions.
Affected Systems
WordPress sites that use the Dokan (Inc.) plugin version 5.0.10 or earlier are impacted. The issue affects the plugin’s role‑based permission controls, and is fixed in version 5.0.11 and later. Sites with any user role that has been maliciously or accidentally granted access could be exploited.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Because the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of widespread exploitation is currently uncertain. The attack vector likely requires an authenticated user with a lower‑level role; no remote code execution or denial‑of‑service impact is described. As a result, while the risk is not low, the system is vulnerable primarily to unauthorized privilege enhancement rather than catastrophic compromise.
OpenCVE Enrichment