CVE-2026-16574
Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.
| Vendor | unknown |
| Product | dokan: ai powered woocommerce multivendor marketplace solution |
| Published | Aug 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown dokan: ai powered woocommerce multivendor marketplace solution
Be the first to know when new unknown vulnerabilities affecting unknown dokan: ai powered woocommerce multivendor marketplace solution are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
0 < 5.0.11
References
Credits
Sai Praneeth Koti WPScan