
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14977 is an Insecure Direct Object Reference (IDOR) vulnerability in the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress, affecting versions up to and including 4.2.4. The flaw exists in the /wp-json/dokan/v1/settings REST API endpoint and allows authenticated attackers with customer-level permissions or above to read or modify other vendors' store settings, including sensitive payment information. The CVE was published on January 20, 2026, with Wordfence as the reporting CNA. It carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Feedly).
The root cause is classified as CWE-284 (Improper Access Control), specifically an IDOR arising from missing validation on a user-controlled key in the StoreSettingController.php file within the Dokan plugin's REST API layer (Wordfence). The vulnerable code paths are located at lines 85, 109, 131, and 152 of includes/REST/StoreSettingController.php, where the plugin fails to verify that the requesting user owns the vendor store being accessed or modified (WordPress Trac). An attacker only needs a valid WordPress account with customer-level access — no elevated privileges are required — and can craft REST API requests referencing arbitrary vendor IDs to read or overwrite their settings. A patch changeset was committed to the plugin repository addressing these validation gaps (WordPress Changeset).
Successful exploitation allows an authenticated attacker to read sensitive financial data from any vendor on the marketplace, including PayPal email addresses, bank account numbers, routing numbers, IBAN, and SWIFT codes, as well as personal contact information such as phone numbers and addresses (Feedly). More critically, an attacker can modify a victim vendor's PayPal email address to one they control, redirecting future marketplace payouts and enabling direct financial theft. The impact is limited to confidentiality and integrity — availability is not affected — but the financial fraud potential makes this a high-severity issue for any WooCommerce multivendor marketplace running the affected plugin versions.
As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.025% (0.000250), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low barrier to exploitation — requiring only a customer-level account — and the direct financial theft potential make it an attractive target if widely publicized.
GET /wp-json/dokan/v1/stores) to enumerate active vendor store IDs on the marketplace./wp-json/dokan/v1/settings with a user-controlled key referencing a target vendor's ID to retrieve their store settings, including payment details (PayPal email, bank account, IBAN, SWIFT)./wp-json/dokan/v1/settings with the target vendor's ID and a modified paypal_email field set to an attacker-controlled address./wp-json/dokan/v1/settings from customer-level accounts, especially GET or PUT requests referencing vendor IDs that do not belong to the authenticated user; repeated API calls to this endpoint from a single IP or user account in a short timeframe.GET or POST /wp-json/dokan/v1/settings requests from non-vendor user accounts; authentication logs showing customer accounts accessing vendor-specific API endpoints.Administrators should upgrade the Dokan plugin beyond version 4.2.4 as soon as a patched release is available; the fix was committed to the plugin repository in changeset 3432750 (WordPress Changeset). As an interim measure, restrict access to the /wp-json/dokan/v1/settings REST API endpoint at the network or web server level (e.g., via WAF rules or .htaccess) to limit exposure. Marketplace operators should also audit recent changes to vendor payment settings and monitor for unauthorized modifications to PayPal email addresses or bank account details (Feedly).
Wordfence, the reporting CNA, published a threat intelligence entry covering the vulnerability and included it in their weekly WordPress vulnerability report for January 19–25, 2026 (Wordfence Weekly Report). The vulnerability was also referenced in the CISA vulnerability bulletin for the week of January 19, 2026 (CISA Bulletin). Social media activity was limited to automated CVE notification accounts on Mastodon and Bluesky, with no significant researcher commentary or broader community discussion observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."