PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16564 Dokan CVE debrief

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.

Vendor
Dokan
Product
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-03
Advisory published
2026-08-03
Advisory updated
2026-08-03

Who should care

Users of Dokan plugin, WooCommerce marketplace owners, security teams responsible for monitoring and responding to potential security incidents, and operators of e-commerce platforms using Dokan and WooCommerce should be aware of this vulnerability. They should verify order ownership in REST endpoint for bulk order-status changes and ensure that proper authorization checks are in place to prevent unauthorized modifications to order statuses. Additionally, they should monitor for suspicious order status changes and have incident response plans in place in case of a security breach. Security teams should also consider implementing compensating controls, such as additional logging and monitoring, to detect and respond to potential security incidents related to this vulnerability. Asset inventory management is also crucial to identify and prioritize affected systems for remediation. Rollback/change windows should be planned to apply patches or mitigations with minimal disruption to business operations. Source tracking is essential to verify the effectiveness of security controls and detect potential security breaches. The CVE record was published on 2026-08-03T07:16:41.983Z and has not been modified since then, providing a reliable source of information for security teams to assess and mitigate this vulnerability. CVE and NVD provide official details on this vulnerability, while WPScan offers additional insights into the vulnerability. Contact WPScan for further information on this issue. Security teams should review the official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets that need extra review should be checked. Exceptions, retest remediated assets, and close the item only after evidence is documented. Security teams should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. The CVE and NVD, 3

Technical summary

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace. This could lead to unauthorized changes in order status, potentially impacting vendors and customers. The vulnerability exists due to a lack of proper authorization checks in the REST endpoint.

Defensive priority

Vendor should verify order ownership in REST endpoint for bulk order-status changes.

Recommended defensive actions

  • Verify order ownership in REST endpoint for bulk order-status changes
  • Update Dokan plugin to version 5.0.9 or later
  • Monitor for suspicious order status changes
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes. Evidence from WPScan indicates vulnerability in Dokan plugin before 5.0.9. WPScan found that users with a Dokan vendor account can modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers. Defenders should verify order ownership in REST endpoint for bulk order-status changes and monitor for suspicious order status changes.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T07:16:41.983Z and has not been modified since then.