SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16565

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Dokan plugin for WordPress prior to version 5.0.9 is vulnerable as it fails to verify product ownership on its REST write endpoints, enabling users with vendor accounts to alter product attributes of other vendors' listings. This could lead to unauthorized modifications, potentially affecting product integrity and vendor trust within the marketplace. WordPress site administrators using the Dokan plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16565
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%
WordPress

Original NVD Description

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.