Descrição
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the -id- parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to read any other vendor-s products — including unpublished draft and pending listings — exposing product names, prices, SKUs, and descriptions belonging to other vendors. The permission callbacks for both the collection endpoint and the single-item endpoint only verify the generic vendor capability (-dokan_view_product_menu- / -dokandar-), which every vendor holds, rather than confirming the requested author ID or product ownership matches the authenticated user.
- Publicação
- 2026-06-27 08:16:44
- Versões afetadas
- <=5.0.4
- Tipo
- Aplicação web
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N