CVE-2026-16574: Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16574?
CVE-2026-16574 has a risk score of 45.
How do I fix CVE-2026-16574?
To fix CVE-2026-16574, update the Dokan plugin to version 5.0.11 or later.
What does CVE-2026-16574 affect?
CVE-2026-16574 affects the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin versions before 5.0.11.
What kind of access does CVE-2026-16574 allow?
CVE-2026-16574 allows authenticated vendors to improperly access downloadable products not owned by them.
When was CVE-2026-16574 published?
CVE-2026-16574 was published on August 8, 2026.