CVE Database /
CVE-2026-16574
CVE
CVE-2026-16574 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.11
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-16574
|
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.11 |
Authorization Bypass Through User-Controlled Key |
Unknown
|
< 5.0.11
|
5.0.11 |
2026-08-08 |
—
|
CVE-2026-16574
A vulnerability exists in Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin versions prior to 5.0.11. The issue arises from a lack of verification that a downloadable product is associated with the requesting vendor before allowing download access via an order REST endpoint, enabling an authenticated vendor to grant their customers unrestricted access to another vendor's paid digital products. This flaw can be exploited by vendors to circumvent payment requirements for other vendors' files.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings