CVE · High

CVE-2025-14977 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 4.2.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14977 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 4.2.5 Improper Access Control High 8.1 < 4.2.5 4.2.5 2026-01-19

CVE-2025-14977

Authenticated users with customer-level permissions or higher can exploit a vulnerability in Dokan plugin versions up to 4.2.4 through the `/wp-json/dokan/v1/settings` REST API endpoint. This issue arises from inadequate validation of user-controlled keys, allowing attackers to access and manipulate sensitive vendor data, including payment details and contact information. As a result, malicious users can intercept payouts by altering PayPal email addresses to their own accounts.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.