CyberRota Analysis
AI-GeneratedThe Dokan plugin for WordPress versions prior to 5.0.14 is vulnerable due to insufficient access controls on its unauthenticated store REST endpoints, allowing any unauthenticated user to access sensitive vendor commission configurations. This exposure can lead to unauthorized disclosure of a vendor's commission type and rates, potentially impacting the vendor's business strategy and competitive position. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when category-based commission is configured, the per-category and default commission rates.