CVE · Medium

CVE-2023-34382 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.20

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-34382 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.20 Deserialization of Untrusted Data Medium 4.4 < 3.7.20 3.7.20 2023-06-07

CVE-2023-34382

The Dokan multivendor marketplace plugin for WordPress contains a PHP Object Injection flaw in versions 3.7.19 and earlier, triggered through the 'create_dummy_vendor' function when the 'import' REST API endpoint is invoked. Authenticated users holding Shop Manager role or higher can exploit this to inject malicious PHP objects through deserialization of unvalidated input. While no known POP chain exists within Dokan itself, the presence of a gadget chain in another installed plugin or theme could enable attackers to perform file deletion, data extraction, or arbitrary code execution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.