The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller, which re-registers WooCommerce's customer CRUD routes under the `/dokan/v1/customers/` namespace and replaces WooCommerce's native `manage_woocommerce` capability check with a vendor-only check that insp [truncated]
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4. This vulnerability allows authenticated attackers, with subscriber-level access and above, to read any other vendor's products, including unpublished draft and pending listings. The vulnera [truncated]
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4. This vulnerability is due to insufficient input sanitization and output escaping. An authenticated attacker with custom-level access and above can inject arbitrary web scripts in [truncated]
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) in versions up to and including 5.0.3. This vulnerability allows authenticated attackers with custom vendor-level access and above to modify arbitrary orders, add notes to any order, delete order notes or WordPress comments, inject fake shipping tracking informat [truncated]