← Späť na vyhľadávanie CVE

CVE-2026-11987

Dokan

Popis

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the -id- parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to read any other vendor-s products — including unpublished draft and pending listings — exposing product names, prices, SKUs, and descriptions belonging to other vendors. The permission callbacks for both the collection endpoint and the single-item endpoint only verify the generic vendor capability (-dokan_view_product_menu- / -dokandar-), which every vendor holds, rather than confirming the requested author ID or product ownership matches the authenticated user.

CVSS 4.3EPSS 0.269%Riziko 0.44
Zobraziť zdroj
Zverejnené
2026-06-27 08:16:44
Dotknuté verzie
<=5.0.4
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N