Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Information

Software Type Plugin
Software Slug dokan-lite (view on wordpress.org)
Software Status Active
Software Author dokaninc
Software Website dokan.co
Software Downloads 4,444,600
Software Active Installs 30,000
Software Record Last Updated August 12, 2026

17 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Dokan <= 3.7.5 - Unauthenticated SQL Injection Patched CVE-2022-3915 9.8 cydave November 21, 2022
Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation Patched CVE-2026-8761 8.8 kai63001 August 4, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.2 - Authenticated (Customer+) Privilege Escalation Patched CVE-2026-49780 8.8 Nguyen Ba Khanh June 3, 2026
Dokan <= 3.6.5 - Cross-Site Request Forgery Patched CVE-2022-3194 8.8 September 28, 2022
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure Patched CVE-2025-14977 8.1 shark3y January 19, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2026-57706 7.2 daroo July 10, 2026
Dokan <= 4.1.3 - Authenticated (Shop Manager+) Privilege Escalation Patched CVE-2025-53425 7.2 Phat RiO September 20, 2025
Dokan <= 3.7.12 - Authenticated (Vendor+) SQL Injection Patched CVE-2023-26525 7.2 Rafie Muhammad March 2, 2023
Dokan <=3.7.19 - Authenticated(Shop Manager+) PHP Object Injection via create_dummy_vendor Patched CVE-2023-34382 6.6 Theodoros Malachias June 7, 2023
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU Patched CVE-2026-11783 6.4 hackthesoul June 26, 2026
Dokan <= 3.6.3 - Authenticated (Vendor+) Stored Cross-Site Scripting Patched CVE-2022-3194 5.5 Veshraj Ghimire September 13, 2022
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API Endpoint Patched CVE-2026-3504 5.3 Rafshanzani Suhada May 1, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.10 - Missing Authorization Patched CVE-2026-66699 4.3 Ananda Dhakal July 29, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter Patched CVE-2026-11987 4.3 0xHerc June 26, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers Patched CVE-2026-10023 4.3 alex_henry20 June 17, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Missing Authorization Patched CVE-2026-24359 4.3 daroo March 16, 2026
Dokan <= 3.0.8 - Cross-Site Request Forgery Bypass Patched CVE-2020-36748 4.3 Jerome Bruandet September 16, 2020

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation