CVE

CVE-2026-16564 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16564 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.9 Authorization Bypass Through User-Controlled Key Unknown < 5.0.9 5.0.9 2026-08-03

CVE-2026-16564

A vulnerability exists in the Dokan plugin for WooCommerce marketplaces prior to version 5.0.9, where an attacker can exploit a REST endpoint that handles bulk order-status updates without properly checking ownership of those orders. As a result, any user with a vendor account on the marketplace can manipulate the status of all orders, including those belonging to other vendors and customers. This issue affects marketplaces running versions of Dokan prior to 5.0.9.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.