The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
History

Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress
Vendors & Products Dokan
Dokan ai Powered Woocommerce Multivendor Marketplace Solution
Wordpress
Wordpress wordpress

Mon, 03 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
Title Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-03T06:00:14.630Z

Updated: 2026-08-03T17:30:41.066Z

Reserved: 2026-07-22T12:39:47.324Z

Link: CVE-2026-16565

cve-icon Vulnrichment

Updated: 2026-08-03T17:15:54.562Z

cve-icon NVD

No data.

cve-icon Redhat

No data.