๐Ÿ” CVE Alert

CVE-2026-16564

UNKNOWN 0.0

Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.

Vendor unknown
Product dokan: ai powered woocommerce multivendor marketplace solution
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown dokan: ai powered woocommerce multivendor marketplace solution

Be the first to know when new unknown vulnerabilities affecting unknown dokan: ai powered woocommerce multivendor marketplace solution are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
0 < 5.0.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/293f5040-5831-483a-9e63-cbbcb3e7d28f/

Credits

Shivamani Vastrala WPScan