CVE · Medium

CVE-2026-66699 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-66699 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.11 Missing Authorization Medium 5.3 < 5.0.11 5.0.11 2026-07-29

CVE-2026-66699

The Dokan plugin for WooCommerce has a security flaw that allows certain users with elevated permissions to bypass intended access controls. In versions of the plugin up to 5.0.10, a capability check is absent from a specific function, enabling authenticated attackers with higher-level roles or custom permissions to execute unauthorized actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.