Junglewise Threat Intelligence

CVE-2026-65495: Dokan Multivendor Dokan Pro broken access control

CVE-2026-65495 · Severity: high · CVSS 7.5 · Published 2026-07-23

Technologies: weDevs Dokan Pro. Vendors: weDevs.

Executive brief

Dokan Pro, a popular WordPress plugin used to create multi-vendor marketplaces, contains a security flaw that allows unauthorized users to perform actions they should not be able to access. An attacker could exploit this to disrupt site operations or delete data without needing a password or account. As of the latest report, no official patch has been released by the developer, though third-party mitigation rules are available.

Technical details

A broken access control vulnerability (CWE-862) exists in the Dokan Pro plugin for WordPress through version 5.0.3. The flaw stems from a missing authorization check on a specific endpoint, allowing unauthenticated remote attackers to execute functions that should be restricted to administrative users. According to the advisory, the vulnerability specifically allows for unauthorized deletions. While a CVSS score of 7.5 is assigned, the vector indicates a high impact on availability (A:H) but no impact on confidentiality or integrity, though the advisory notes it could lead to unauthorized vendor-initiated deletions. No official patch is currently available.

Affected products

  • Dokan Multivendor Plugin Dokan Pro <= 5.0.3

Timeline

  • 2026-06-11: disclosed: Reported by VanTastic to Patchstack
  • 2026-07-23: advisory: Public advisory published by Patchstack and NVD

References

Related threats