Junglewise Threat Intelligence

CVE-2026-11987: weDevs Dokan IDOR in REST API Product Controller

CVE-2026-11987 · Severity: medium · CVSS 4.3 · Published 2026-06-27

Technologies: weDevs Dokan. Vendors: weDevs.

Executive brief

The Dokan plugin for WordPress, which allows users to build multi-vendor marketplaces like Amazon or Etsy, contains a security flaw that allows registered vendors to view private information belonging to other sellers. An authenticated user can access unpublished product drafts, pending listings, prices, and SKUs that should not be visible to them. This could lead to the exposure of sensitive business data and competitive intelligence between marketplace participants.

Technical details

The Dokan plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) via the 'id' parameter in its REST API endpoints. The root cause is a failure in the permission callbacks for both the collection and single-item endpoints, which only verify generic vendor capabilities ('dokan_view_product_menu' or 'dokandar') rather than validating that the requested product belongs to the authenticated user. An attacker with subscriber-level access or higher can exploit this to read sensitive details of any vendor's products, including unpublished drafts and pending listings. This affects all versions up to and including 5.0.4.

Affected products

  • weDevs Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Up to and including 5.0.4

Timeline

  • 2026-06-27: disclosed: CVE published to NVD dataset

References

Related threats