Junglewise Threat Intelligence

CVE-2026-16577: Dokan reverse withdrawal ledger manipulation via client-supplied amount

CVE-2026-16577 · Severity: low · CVSS 2.7 · Published 2026-08-21

Technologies: weDevs Dokan. Vendors: weDevs.

Executive brief

Dokan is a WooCommerce plugin that enables multi-vendor marketplace functionality, including a reverse-withdrawal feature that allows vendors to settle commission debts. The plugin fails to validate payment amounts submitted by vendors, allowing an approved vendor to credit their account with an arbitrary amount and eliminate their real commission debt without actually paying. This permits vendors to avoid payment obligations while the marketplace loses revenue.

Technical details

The vulnerability is an authorization bypass in the reverse-withdrawal payment processing logic (CWE-863). When a vendor submits a payment amount via the REST API endpoint `/wp-json/dokan/v1/reverse-withdrawal/add-to-cart`, the plugin does not validate that the supplied amount matches the vendor's actual outstanding balance. The attacker must be an authenticated, approved vendor with a real due commission balance. An attacker can craft a reverse-withdrawal cart item with an inflated amount, complete checkout using Cash on Delivery (which requires no actual payment), and after the marketplace admin marks the order completed, the plugin credits the full arbitrary amount to the vendor's ledger. The plugin was patched in version 5.0.14.

Affected products

  • Wedevs Dokan before 5.0.14

Timeline

  • 2026-08-19: disclosed
  • 2026-05-14: patched: Fixed in version 5.0.14

References

Related threats