Junglewise Threat Intelligence

CVE-2026-49780: weDevs Dokan privilege escalation in WordPress plugin

CVE-2026-49780 · Severity: high · CVSS 8.8 · Published 2026-06-15

Technologies: weDevs Dokan. Vendors: weDevs.

Executive brief

Dokan is a popular WordPress plugin used to create multi-vendor marketplaces. A security flaw in versions 5.0.2 and earlier allows users with basic 'Customer' accounts to gain higher-level administrative permissions. This could allow an attacker to take full control of the website, access sensitive business data, or disrupt marketplace operations.

Technical details

The Dokan plugin for WordPress (versions up to and including 5.0.2) is vulnerable to privilege escalation due to incorrect privilege assignment (CWE-266). An attacker authenticated with a low-level 'Customer' role can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to escalate their privileges to a higher level, potentially gaining full administrative control over the WordPress site. The issue is addressed in version 5.0.3.

Affected products

  • weDevs Dokan <= 5.0.2

Timeline

  • 2026-04-29: other: Reported by Nguyen Ba Khanh
  • 2026-06-03: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: CVE published to NVD

References

Related threats