Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Information

Software Type Plugin
Software Slug dokan-lite (view on wordpress.org)
Software Status Active
Software Author dokaninc
Software Website dokan.co
Software Downloads 4,392,273
Software Active Installs 40,000
Software Record Last Updated July 13, 2026

14 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter Patched CVE-2026-11987 4.3 0xHerc June 26, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU Patched CVE-2026-11783 6.4 hackthesoul June 26, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers Patched CVE-2026-10023 4.3 Kirasec June 17, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.2 - Authenticated (Customer+) Privilege Escalation Patched CVE-2026-49780 8.8 Nguyen Ba Khanh June 3, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API Endpoint Patched CVE-2026-3504 5.3 Rafshanzani Suhada May 1, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Missing Authorization Patched CVE-2026-24359 4.3 daroo March 16, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure Patched CVE-2025-14977 8.1 shark3y January 19, 2026
Dokan <= 4.1.3 - Authenticated (Shop Manager+) Privilege Escalation Patched CVE-2025-53425 7.2 Phat RiO September 20, 2025
Dokan <=3.7.19 - Authenticated(Shop Manager+) PHP Object Injection via create_dummy_vendor Patched CVE-2023-34382 6.6 Theodoros Malachias June 7, 2023
Dokan <= 3.7.12 - Authenticated (Vendor+) SQL Injection Patched CVE-2023-26525 7.2 Rafie Muhammad March 2, 2023
Dokan <= 3.7.5 - Unauthenticated SQL Injection Patched CVE-2022-3915 9.8 cydave November 21, 2022
Dokan <= 3.6.5 - Cross-Site Request Forgery Patched CVE-2022-3194 8.8 September 28, 2022
Dokan <= 3.6.3 - Authenticated (Vendor+) Stored Cross-Site Scripting Patched CVE-2022-3194 5.5 Veshraj Ghimire September 13, 2022
Dokan <= 3.0.8 - Cross-Site Request Forgery Bypass Patched CVE-2020-36748 4.3 Jerome Bruandet September 16, 2020

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation