CVE-2025-5931: Dokan Pro <= 4.0.5 - Authenticated (Vendor+) Privilege Escalation
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is due to the plugin not properly validating a user's identity prior to updating their password during a staff password reset. This makes it possible for authenticated attackers, with vendor-level access and above, to elevate their privilege to the level of a staff member and then change arbitrary user passwords, including those of administrators in order to gain access to their accounts. By default, the plugin allows customers to become vendors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5931?
CVE-2025-5931 is considered a critical vulnerability due to its potential for privilege escalation via account takeover.
How do I fix CVE-2025-5931?
To fix CVE-2025-5931, update the Dokan Pro plugin to version 4.0.6 or later.
What is the exploit method for CVE-2025-5931?
CVE-2025-5931 can be exploited by an attacker who can manipulate a staff password reset process without proper identity verification.
Which versions of Dokan Pro are affected by CVE-2025-5931?
All versions of Dokan Pro up to and including 4.0.5 are affected by CVE-2025-5931.
Can CVE-2025-5931 lead to unauthorized access?
Yes, CVE-2025-5931 may allow attackers to gain unauthorized access to user accounts through privilege escalation.