Junglewise Threat Intelligence

CVE-2026-57706: Dokan Dokan-lite Reflected XSS

CVE-2026-57706 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

Dokan is a popular WordPress plugin used to create multi-vendor marketplaces. A security flaw in the 'lite' version of this plugin allows attackers to trick site administrators or visitors into clicking a malicious link, which then executes unauthorized scripts in their browser. This can lead to unauthorized actions being performed on the site, redirection to malicious websites, or the theft of sensitive session information.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Dokan-lite plugin for WordPress due to improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by crafting a malicious URL and tricking a user (typically an administrator or logged-in user) into clicking it. Upon interaction, the malicious script is executed within the context of the victim's browser session. This can be used to steal session cookies, perform actions on behalf of the user, or deface the site. The issue is fixed in version 5.0.7.

Affected products

  • Dokan, Inc. Dokan (dokan-lite) <= 5.0.6

Timeline

  • 2026-06-20: other: Reported by researcher daroo
  • 2026-07-10: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD
  • 2026-07-13: patched: Version 5.0.7 released to address the vulnerability

References