CVE Database /
CVE-2023-34382
CVE · Medium
CVE-2023-34382 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.20
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-34382
|
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.20 |
Deserialization of Untrusted Data |
Medium
4.4
|
< 3.7.20
|
3.7.20 |
2023-06-07 |
—
|
CVE-2023-34382
The Dokan multivendor marketplace plugin for WordPress contains a PHP Object Injection flaw in versions 3.7.19 and earlier, triggered through the 'create_dummy_vendor' function when the 'import' REST API endpoint is invoked. Authenticated users holding Shop Manager role or higher can exploit this to inject malicious PHP objects through deserialization of unvalidated input. While no known POP chain exists within Dokan itself, the presence of a gadget chain in another installed plugin or theme could enable attackers to perform file deletion, data extraction, or arbitrary code execution.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings