CVE · Medium

CVE-2022-3194 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.6.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3194 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.6.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.6.6 3.6.6 2022-09-13

CVE-2022-3194

The Dokan plugin for WordPress through version 3.6.3 contains a stored cross-site scripting vulnerability in the product reviews feature, arising from improper handling of user input and output. Authenticated users with vendor-level permissions or higher can inject malicious scripts that execute when other users view affected pages because the plugin grants the unfiltered_html capability to these roles. This vulnerability was resolved in version 3.6.6.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.