CVE

CVE-2026-16574 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16574 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.11 Authorization Bypass Through User-Controlled Key Unknown < 5.0.11 5.0.11 2026-08-08

CVE-2026-16574

A vulnerability exists in Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin versions prior to 5.0.11. The issue arises from a lack of verification that a downloadable product is associated with the requesting vendor before allowing download access via an order REST endpoint, enabling an authenticated vendor to grant their customers unrestricted access to another vendor's paid digital products. This flaw can be exploited by vendors to circumvent payment requirements for other vendors' files.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.