SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16577

LOW · CVSS 2.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Dokan plugin for WordPress versions prior to 5.0.14 is vulnerable as it fails to validate the payment amount provided by vendors against their actual outstanding balance during reverse-withdrawal transactions. This flaw allows vendors to manipulate their reverse-withdrawal ledger, potentially enabling them to eliminate legitimate commission debts without making the required payments. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of financial exploitation.

CVE
CVE-2026-16577
Severity
LOW
CVSS
2.7
EPSS
0.17%
WordPress

Original NVD Description

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.