Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.4epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
public PoCs found — 1
cve_referencewpscan.com/vulnerability/b38dc6a4-a590-402f-88e1-3624a22c7348/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.