CVE · High

CVE-2026-8761 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8761 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 5.0.3 Missing Authorization High 8.8 < 5.0.3 5.0.3 2026-08-04

CVE-2026-8761

The Dokan plugin for WordPress contains a vulnerability that allows unauthorized access to user data and capabilities. In versions up to 5.0.1, the CustomersController REST controller fails to verify the requesting user's permissions when modifying or deleting users, effectively bypassing WooCommerce's native security checks. This flaw enables attackers with vendor-level access to manipulate any WordPress user, including administrators, through targeted API requests.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.