AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16574

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Dokan plugin for WordPress prior to version 5.0.11 has a vulnerability that allows authenticated vendors to bypass download permissions, enabling them to grant their customers access to paid downloadable products from other vendors. This flaw poses a significant risk of revenue loss for affected vendors and undermines the integrity of the marketplace. WordPress site administrators using the Dokan plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16574
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
WordPress

Original NVD Description

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.