CyberRota Analysis
AI-GeneratedThe Dokan plugin for WordPress prior to version 5.0.11 has a vulnerability that allows authenticated vendors to bypass download permissions, enabling them to grant their customers access to paid downloadable products from other vendors. This flaw poses a significant risk of revenue loss for affected vendors and undermines the integrity of the marketplace. WordPress site administrators using the Dokan plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.