Junglewise Threat Intelligence

CVE-2026-65492: weDevs Dokan Pro unauthenticated XSS

CVE-2026-65492 · Severity: high · CVSS 7.1 · Published 2026-07-23

Technologies: weDevs Dokan Pro. Vendors: weDevs.

Executive brief

Dokan Pro is a popular WordPress plugin used to create multi-vendor marketplaces. A security flaw allows unauthenticated attackers to inject malicious scripts into the website, which could lead to unauthorized redirects, theft of user session data, or the display of fraudulent content to visitors. This occurs when a site administrator or visitor interacts with a specially crafted link or page created by the attacker.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Dokan Pro plugin for WordPress (versions <= 5.0.0) due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is exploitable by unauthenticated remote attackers via a network-based attack vector. Successful exploitation requires a victim (such as a site administrator) to perform an action, such as clicking a malicious link (User Interaction: Required). This can result in the execution of arbitrary JavaScript, potentially leading to session hijacking or unauthorized administrative actions. As of the advisory date, no official patch has been released.

Affected products

  • weDevs Dokan Pro <= 5.0.0

Timeline

  • 2026-04-30: other: Reported by researcher dutafi
  • 2026-07-23: advisory: Public disclosure by Patchstack and NVD

References

Related threats