CVE-2026-65492: WordPress Dokan Pro plugin < 5.0.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Dokan Pro allows Reflected XSS.
This issue affects Dokan Pro: from n/a before 5.0.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Dokan Pro pluginto a version that resolves this vulnerability.Fixed in 5.0.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65492?
The severity of CVE-2026-65492 is rated as high with a score of 7.1.
What type of vulnerability is CVE-2026-65492?
CVE-2026-65492 is an unauthenticated Cross Site Scripting (XSS) vulnerability.
Which versions of the Dokan Pro plugin are affected by CVE-2026-65492?
CVE-2026-65492 affects Dokan Pro plugin versions up to and including 5.0.0.
How do I fix CVE-2026-65492?
To fix CVE-2026-65492, update the Dokan Pro plugin to a version newer than 5.0.0.
What are the potential impacts of CVE-2026-65492?
The potential impacts of CVE-2026-65492 include the possibility of an attacker executing arbitrary scripts in the context of a user's browser.