CVE-2026-16565: Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16565?
CVE-2026-16565 has a medium severity rating of 4.3 according to CVSS 3.1.
How do I fix CVE-2026-16565?
To fix CVE-2026-16565, update the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin to version 5.0.9 or later.
What type of vulnerability is represented by CVE-2026-16565?
CVE-2026-16565 is a cross-vendor product attribute modification vulnerability that affects the product attribute REST API.
Who is affected by CVE-2026-16565?
Users with a Dokan vendor account are affected, as they can modify product attributes of other vendors.
When was CVE-2026-16565 published?
CVE-2026-16565 was published on August 3, 2026.