๐Ÿ” CVE Alert

CVE-2026-16565

UNKNOWN 0.0

Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.

Vendor unknown
Product dokan: ai powered woocommerce multivendor marketplace solution
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown dokan: ai powered woocommerce multivendor marketplace solution

Be the first to know when new unknown vulnerabilities affecting unknown dokan: ai powered woocommerce multivendor marketplace solution are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
0 < 5.0.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/82c341bb-64ad-45ee-9ac7-8d99927f0c0a/

Credits

Sai Praneeth Koti WPScan