CVE · Critical

CVE-2022-3915 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3915 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.7.6 3.7.6 2022-11-21

CVE-2022-3915

The Dokan plugin for WordPress versions up to and including 3.7.5 contains a SQL injection vulnerability in the 'user_ids' parameter of an AJAX action accessible to unauthenticated users. Because the parameter is not properly escaped or prepared before being used in database queries, attackers can inject additional SQL commands to extract sensitive data from the database. This flaw affects unprivileged and unauthenticated users alike, allowing arbitrary SQL query manipulation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.