๐Ÿ” CVE Alert

CVE-2026-16574

UNKNOWN 0.0

Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.

Vendor unknown
Product dokan: ai powered woocommerce multivendor marketplace solution
Published Aug 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown dokan: ai powered woocommerce multivendor marketplace solution

Be the first to know when new unknown vulnerabilities affecting unknown dokan: ai powered woocommerce multivendor marketplace solution are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
0 < 5.0.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b38dc6a4-a590-402f-88e1-3624a22c7348/

Credits

Sai Praneeth Koti WPScan