SecAlerts
dokan logo

dokan

Security Risk Profile

48
/100
medium

Security Risk Score

Comprehensive risk assessment based on 14 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 12, 2022 to present

14
Total CVEs
9
Critical+High
0
Exploited
7
Unpatched

Threat Assessment

Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
48/100
medium
🆕 1Fresh (<7d)📈 2 in Last 30 Days

Severity Distribution

Critical
2
High
7
Medium
5
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
3
2
XSS
2
3
CSRF
1

Most Affected Products

1. Dokan Dokan WordPress6
2. Dokan Dokan: AI Powered WooCommerce Multivendor Marketplace Solution3
3. Dokan Dokan Pro3
4. weDevs Dokan Wordpress2
5. Dokan WooCommerce Multivendor Marketplace Solution1

Recent Vulnerabilities

See more →
CVE-2026-16565
CVSS 4.3medium

Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API

8/3/2026🔧 No Patch
CVE-2026-65493
CVSS 7.5high

WordPress Dokan Pro plugin <= 5.0.2 - PHP Object Injection vulnerability

7/23/2026🔧 No Patch
CVE-2026-12224
CVSS 8.8high

Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint

7/1/2026🔧 No Patch
CVE-2026-11783
CVSS 6.4medium

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU

6/27/2026🔧 No Patch
CVE-2026-11987
CVSS 4.3medium

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter

6/27/2026🔧 No Patch
CVE-2025-14977
CVSS 8.1high

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure

1/20/2026🔧 No Patch
CVE-2025-53425
CVSS 7.2high

WordPress Dokan plugin <= 4.1.3 - Privilege Escalation vulnerability

10/22/2025🔧 No Patch
CVE-2025-5931
CVSS 8.8high

Dokan Pro <= 4.0.5 - Authenticated (Vendor+) Privilege Escalation

8/26/2025🔧 No Patch
CVE-2024-3922
CVSS 10.0critical

Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection

6/13/2024🔧 No Patch
CVE-2022-3194
CVSS 5.4medium

Dokan < 3.6.4 - Vendor Stored Cross-Site Scripting

1/16/2024🔧 No Patch

Monitor dokan in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.