Junglewise Threat Intelligence

CVE-2026-11783: weDevs Dokan Stored XSS via Product SKU

CVE-2026-11783 · Severity: medium · CVSS 6.4 · Published 2026-06-27

Technologies: weDevs Dokan. Vendors: weDevs.

Executive brief

The Dokan plugin for WordPress, which allows users to build multi-vendor marketplaces like Amazon or eBay, contains a security flaw. Authenticated vendors or users with certain permissions can inject malicious scripts into product identifiers. These scripts are then executed in the browsers of other site visitors, including customers and administrators, potentially leading to unauthorized actions or data theft.

Technical details

The Dokan plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the Product SKU field in all versions up to and including 5.0.4. The root cause is insufficient input sanitization and output escaping of the SKU value. An authenticated attacker with 'custom-level' access or higher can inject arbitrary web scripts. These scripts are subsequently executed in the context of other users' browsers when the store search widget processes an unescaped AJAX response using jQuery's .html() method. This vulnerability allows for script execution against both authenticated and unauthenticated site visitors.

Affected products

  • weDevs Dokan: AI Powered WooCommerce Multivendor Marketplace Solution up to, and including, 5.0.4

Timeline

  • 2026-06-27: disclosed
  • 2026-06-27: advisory

References

Related threats