Executive brief
Dokan Pro is a popular WordPress plugin used to create multi-vendor marketplaces like Amazon or Etsy. A security flaw in the plugin allows logged-in users with basic 'Subscriber' permissions to perform unauthorized database queries. This could lead to the theft of sensitive business information, customer data, or site configuration details from the website's database.
Technical details
The Dokan Pro plugin for WordPress is vulnerable to time-based SQL injection due to insufficient escaping of the 'orderby' parameter and a lack of proper preparation in the existing SQL query. This vulnerability allows authenticated attackers with Subscriber-level access or higher to append malicious SQL commands to legitimate queries. By leveraging time-based techniques, an attacker can extract sensitive information from the database. The issue affects all versions up to and including 5.0.4. Users are advised to update to a patched version if available.
Affected products
- weDevs Dokan Pro <= 5.0.4
Timeline
- 2026-06-25: disclosed: NVD publication date
- 2026-06-25: advisory: Wordfence advisory published