SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-16575

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Dokan plugin for WordPress versions prior to 5.0.14 is vulnerable due to insufficient access controls on its unauthenticated store REST endpoints, allowing any unauthenticated user to access sensitive vendor commission configurations. This exposure can lead to unauthorized disclosure of a vendor's commission type and rates, potentially impacting the vendor's business strategy and competitive position. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16575
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when category-based commission is configured, the per-category and default commission rates.