← Retour à la recherche de CVE

CVE-2026-11987

Dokan

Description

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the -id- parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to read any other vendor-s products — including unpublished draft and pending listings — exposing product names, prices, SKUs, and descriptions belonging to other vendors. The permission callbacks for both the collection endpoint and the single-item endpoint only verify the generic vendor capability (-dokan_view_product_menu- / -dokandar-), which every vendor holds, rather than confirming the requested author ID or product ownership matches the authenticated user.

CVSS 4.3EPSS 0.269%Risque 0.44
Voir la source
Publication
2026-06-27 08:16:44
Versions concernées
<=5.0.4
Type
Application web
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N