Extension WordPress

Vulnérabilités Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Cette page rassemble les failles publiées pour Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy, leurs plages de versions affectées et les correctifs signalés dans la base locale.

15Vulnérabilités
1Critiques
15Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

15 fiches

CVE-2026-57706 Élevée · 7,2
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 – Unauthenticated Stored Cross-Site Scripting

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.6 due to insufficient input sanitization and output…

Versions affectées

*-5.0.6

Correctif

5.0.7

Publication

10/07/2026

CVE-2026-11987 Moyenne · 4,3
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 – Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due…

Versions affectées

*-5.0.4

Correctif

5.0.5

Publication

26/06/2026

CVE-2026-11783 Moyenne · 6,4
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 – Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient…

Versions affectées

*-5.0.4

Correctif

5.0.5

Publication

26/06/2026

CVE-2026-10023 Moyenne · 4,3
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 – Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note,…

Versions affectées

*-5.0.3

Correctif

5.0.4

Publication

17/06/2026

CVE-2026-49780 Élevée · 8,8
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.2 – Authenticated (Customer+) Privilege Escalation

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.2. This makes it possible for authenticated attackers,…

Versions affectées

*-5.0.2

Correctif

5.0.3

Publication

03/06/2026

CVE-2026-3504 Moyenne · 5,3
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 – Unauthenticated Information Disclosure in Store Reviews REST API Endpoint

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due to the 'prepare_reviews_for_response' method…

Versions affectées

*-4.3.1

Correctif

4.3.2

Publication

01/05/2026

CVE-2026-24359 Moyenne · 4,3
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 – Missing Authorization

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and…

Versions affectées

*-4.2.4

Correctif

4.2.5

Publication

16/03/2026

CVE-2025-14977 Élevée · 8,1
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 – Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint…

Versions affectées

*-4.2.4

Correctif

4.2.5

Publication

19/01/2026

CVE-2025-53425 Élevée · 7,2
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan <= 4.1.3 – Authenticated (Shop Manager+) Privilege Escalation

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers,…

Versions affectées

*-4.1.3

Correctif

4.1.4

Publication

20/09/2025

CVE-2023-34382 Moyenne · 6,6
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan <=3.7.19 – Authenticated(Shop Manager+) PHP Object Injection via create_dummy_vendor

The Dokan plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7.19 via deserialization of untrusted input via the 'create_dummy_vendor' function called by the 'import' REST API endpoint. This allows authenticated attackers…

Versions affectées

[*, 3.7.20)

Correctif

3.7.20

Publication

07/06/2023

CVE-2023-26525 Élevée · 7,2
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan <= 3.7.12 – Authenticated (Vendor+) SQL Injection

The Dokan plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and including, 3.7.12 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL…

Versions affectées

*-3.7.12

Correctif

3.7.13

Publication

02/03/2023

CVE-2022-3915 Critique · 9,8
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan <= 3.7.5 – Unauthenticated SQL Injection

The Dokan plugin for WordPress is vulnerable to SQL Injection via the ‘user_ids’ parameter in versions up to, and including, 3.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

Versions affectées

*-3.7.5

Correctif

3.7.6

Publication

21/11/2022

CVE-2022-3194 Élevée · 8,8
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan <= 3.6.5 – Cross-Site Request Forgery

The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.5. This is due to missing or incorrect nonce validation on the setup_wizard function. This makes it possible for unauthenticated attackers…

Versions affectées

*-3.6.5

Correctif

3.6.6

Publication

28/09/2022

CVE-2022-3194 Moyenne · 5,5
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan <= 3.6.3 – Authenticated (Vendor+) Stored Cross-Site Scripting

The Dokan plugin for WordPress is vulnerable to Stored Cross-Site Scripting via product reviews in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with vendor…

Versions affectées

*-3.6.3

Correctif

3.6.4

Publication

13/09/2022

CVE-2020-36748 Moyenne · 4,3
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Dokan <= 3.0.8 – Cross-Site Request Forgery Bypass

The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers…

Versions affectées

[*, 3.0.9)

Correctif

3.0.9

Publication

16/09/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités