Executive brief
Dokan Pro is a WordPress plugin used to create multi-vendor marketplaces like Amazon or Etsy. A security flaw allows users with 'Vendor' level access to grant themselves or others administrative privileges. This could lead to a complete takeover of the website, allowing an attacker to access sensitive customer data, modify site settings, or disrupt business operations.
Technical details
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation due to an insecure implementation of the `update_capabilities()` REST handler. The function accepts arbitrary capability strings from a request body and passes them directly to the `WP_User::add_cap()` function without validating them against an allowlist. While the endpoint checks if the requester has 'dokandar' (vendor) capabilities, it does not prevent them from assigning high-level permissions like 'administrator' to vendor staff accounts. This vulnerability requires the Vendor Staff module to be enabled and can be exploited by any authenticated user with Vendor-level access or higher to achieve full site takeover. All versions up to and including 5.0.4 are affected.
Affected products
- weDevs Dokan Pro up to, and including, 5.0.4
Timeline
- 2026-07-01: advisory: NVD publication date
- 2026-07-01: disclosed: Wordfence vulnerability report published