Executive brief
Dokan is a WordPress plugin that enables marketplace functionality. A broken access control vulnerability allows users with custom roles to view or perform actions they should not have permission to access, such as viewing other users' data or performing unauthorized administrative functions.
Technical details
The vulnerability is a broken access control issue in Dokan versions up to 5.0.10 affecting custom role handling. Users with custom roles can bypass access restrictions and perform actions outside their intended permissions, potentially viewing sensitive data or performing unauthorized administrative operations. The attack requires authentication as a user with a custom role. The vulnerability is present in all versions through 5.0.10 and has been patched in version 5.0.11 or later.
Affected products
- Wedevs Dokan <=5.0.10
Timeline
- 2026-07-29: disclosed
- 2026-07-29: patched: patched in version 5.0.11