CVE Database /
CVE-2026-16564
CVE
CVE-2026-16564 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-16564
|
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.9 |
Authorization Bypass Through User-Controlled Key |
Unknown
|
< 5.0.9
|
5.0.9 |
2026-08-03 |
—
|
CVE-2026-16564
A vulnerability exists in the Dokan plugin for WooCommerce marketplaces prior to version 5.0.9, where an attacker can exploit a REST endpoint that handles bulk order-status updates without properly checking ownership of those orders. As a result, any user with a vendor account on the marketplace can manipulate the status of all orders, including those belonging to other vendors and customers. This issue affects marketplaces running versions of Dokan prior to 5.0.9.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings