SecAlerts
d

dokan

Security Risk Profile

42
/100
medium

Security Risk Score

Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 12, 2022 to present

17
Total CVEs
10
Critical+High
0
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
42/100
medium
🆕 1Fresh (<7d)📈 4 in Last 30 Days

Severity Distribution

Critical
2
High
8
Medium
6
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
3
2
XSS
2
3
CSRF
1

Most Affected Products

1. Dokan Dokan WordPress6
2. Dokan Dokan: AI Powered WooCommerce Multivendor Marketplace Solution4
3. Dokan Dokan Pro3
4. weDevs Dokan Wordpress2
5. Dokan WordPress plugin1

Recent Vulnerabilities

See more →
CVE-2026-16577
CVSS 2.7low

Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount

Aug 21, 2026🔧 No Patch
CVE-2026-16574
CVSS 5.4medium

Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint

Aug 8, 2026🔧 No Patch
CVE-2026-8761
CVSS 8.8EPSS 0%high

Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation

Aug 5, 2026🔧 No Patch
CVE-2026-16565
CVSS 4.3medium

Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API

Aug 3, 2026🔧 No Patch
CVE-2026-65493
CVSS 7.5high

WordPress Dokan Pro plugin <= 5.0.2 - PHP Object Injection vulnerability

Jul 23, 2026🔧 No Patch
CVE-2026-12224
CVSS 8.8high

Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint

Jul 1, 2026🔧 No Patch
CVE-2026-11783
CVSS 6.4medium

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU

Jun 27, 2026🔧 No Patch
CVE-2026-11987
CVSS 4.3medium

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter

Jun 27, 2026🔧 No Patch
CVE-2025-14977
CVSS 8.1high

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure

Jan 20, 2026🔧 No Patch
CVE-2025-53425
CVSS 7.2high

WordPress Dokan plugin <= 4.1.3 - Privilege Escalation vulnerability

Oct 22, 2025🔧 No Patch

Monitor dokan in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

dokan Security Vulnerabilities & Risk Score | 17 CVEs | SecAlerts - SecAlerts