Junglewise Threat Intelligence

CVE-2026-56033: Dokan Multivendor Plugin Dokan Pro unauthenticated privilege escalation

CVE-2026-56033 · Severity: critical · CVSS 9.8 · Published 2026-06-26

Technologies: weDevs Dokan Pro. Vendors: weDevs.

Executive brief

Dokan Pro is a popular WordPress plugin used to create multi-vendor marketplaces similar to Amazon or eBay. A critical security flaw allows unauthorized individuals to gain administrative privileges on the website without needing to log in. This could lead to a complete takeover of the marketplace, resulting in the theft of customer data, financial records, and total service disruption.

Technical details

An unauthenticated privilege escalation vulnerability exists in Dokan Pro versions up to and including 5.0.4. The flaw is categorized as CWE-266 (Incorrect Privilege Assignment), which allows a remote, unauthenticated attacker to elevate their privileges to an administrative level. The attack can be executed over the network with low complexity and requires no user interaction. This vulnerability stems from improper permission checks within the plugin's logic. Users are advised to update to version 5.0.5 or later to mitigate this risk.

Affected products

  • Dokan Multivendor Plugin Dokan Pro <= 5.0.4

Timeline

  • 2026-06-26: disclosed: CVE published to NVD dataset
  • 2026-06-26: advisory: Patchstack advisory published

References

Related threats