Executive brief
Dokan Pro, a popular multi-vendor marketplace solution for WordPress, contains a security flaw that allows registered users with low-level 'Subscriber' accounts to inject malicious code. If exploited, an attacker could potentially take control of the website, access sensitive customer data, or disrupt business operations. This vulnerability is particularly dangerous as it can lead to full site compromise if the right conditions are met on the server.
Technical details
Dokan Pro versions 5.0.2 and below are vulnerable to PHP Object Injection (CWE-502). The vulnerability arises from the deserialization of untrusted user input, which can be triggered by an authenticated attacker with at least 'Subscriber' privileges. While the attack complexity is rated as high (AC:H), a successful exploit could allow an attacker to leverage available Property-Oriented Programming (POP) chains to perform remote code execution, SQL injection, or file system manipulation. As of the advisory date, no official patch has been released by the vendor, though third-party mitigation rules are available.
Affected products
- Dokan Dokan Pro <= 5.0.2
Timeline
- 2026-06-06: other: Reported by Expatch
- 2026-07-23: disclosed: Vulnerability published by Patchstack and NVD