Executive brief
Dokan is a WordPress plugin that enables multi-vendor marketplace functionality for WooCommerce sites. The plugin contains a privilege escalation flaw in its admin REST API routes that allows Shop Managers to install and activate arbitrary plugins from WordPress.org—capabilities they should not have. An attacker with Shop Manager access can exploit this to install malicious plugins, achieving code execution on the affected WordPress site.
Technical details
The vulnerability is a broken access control flaw in Dokan's REST API endpoints (/dokan/v1/admin/extensions/install and /dokan/v1/admin/onboarding). The plugin checks only for the manage_woocommerce capability instead of enforcing the install_plugins and activate_plugins capabilities required to install and activate plugins. An authenticated attacker with Shop Manager role (which grants manage_woocommerce but lacks plugin management capabilities) can craft authenticated REST API requests with a valid nonce to install arbitrary plugins from WordPress.org, and use the onboarding endpoint to both install and activate them. The attack requires a valid Shop Manager session and REST nonce but no additional user interaction. The plugin-installation capability check was corrected in version 5.0.14.
Affected products
- Dokan Dokan before 5.0.14
Timeline
- 2026-08-19: disclosed
- 2026-08-21: other: Published on NVD
- 2026-08-21: patched: Fixed in version 5.0.14