Junglewise Threat Intelligence

CVE-2026-65494: Dokan Dokan Pro SQL injection in Subscriber role

CVE-2026-65494 · Severity: high · CVSS 7.1 · Published 2026-07-23

Technologies: weDevs Dokan Pro. Vendors: weDevs.

Executive brief

Dokan Pro, a popular multi-vendor marketplace solution for WordPress, contains a security flaw that allows users with basic 'Subscriber' accounts to perform unauthorized database operations. An attacker could exploit this to steal sensitive information from the website's database, potentially compromising customer data or site configuration. While the vulnerability requires specific conditions to exploit, it poses a significant risk to the confidentiality of the marketplace's data.

Technical details

A SQL injection vulnerability exists in the Dokan Pro plugin for WordPress (versions <= 5.0.2) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to authenticated users with 'Subscriber' privileges. Although the attack complexity is rated as high, a successful exploit allows a remote attacker to execute arbitrary SQL queries against the backend database. This can lead to the extraction of sensitive information or a partial loss of availability. At the time of the advisory, no official patch was available, and users are advised to use mitigation tools like Patchstack.

Affected products

  • Dokan Dokan Pro <= 5.0.2

Timeline

  • 2026-06-07: other: Reported by Expatch
  • 2026-07-23: disclosed: NVD publication date

References

Related threats