CVE-2025-14977: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14977 is an Insecure Direct Object Reference (IDOR) vulnerability in the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress, affecting versions up to and including 4.2.4. The flaw exists in the /wp-json/dokan/v1/settings REST API endpoint and allows authenticated attackers with customer-level permissions or above to read or modify other vendors' store settings, including sensitive payment information. The CVE was published on January 20, 2026, with Wordfence as the reporting CNA. It carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Feedly).

Technical details

The root cause is classified as CWE-284 (Improper Access Control), specifically an IDOR arising from missing validation on a user-controlled key in the StoreSettingController.php file within the Dokan plugin's REST API layer (Wordfence). The vulnerable code paths are located at lines 85, 109, 131, and 152 of includes/REST/StoreSettingController.php, where the plugin fails to verify that the requesting user owns the vendor store being accessed or modified (WordPress Trac). An attacker only needs a valid WordPress account with customer-level access — no elevated privileges are required — and can craft REST API requests referencing arbitrary vendor IDs to read or overwrite their settings. A patch changeset was committed to the plugin repository addressing these validation gaps (WordPress Changeset).

Impact

Successful exploitation allows an authenticated attacker to read sensitive financial data from any vendor on the marketplace, including PayPal email addresses, bank account numbers, routing numbers, IBAN, and SWIFT codes, as well as personal contact information such as phone numbers and addresses (Feedly). More critically, an attacker can modify a victim vendor's PayPal email address to one they control, redirecting future marketplace payouts and enabling direct financial theft. The impact is limited to confidentiality and integrity — availability is not affected — but the financial fraud potential makes this a high-severity issue for any WooCommerce multivendor marketplace running the affected plugin versions.

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.025% (0.000250), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low barrier to exploitation — requiring only a customer-level account — and the direct financial theft potential make it an attractive target if widely publicized.

Exploitation steps

  1. Obtain a low-privilege account: Register or obtain a customer-level (or higher) WordPress account on a target marketplace running Dokan plugin version 4.2.4 or earlier.
  2. Enumerate vendor IDs: Use the Dokan REST API (e.g., GET /wp-json/dokan/v1/stores) to enumerate active vendor store IDs on the marketplace.
  3. Read target vendor settings: Send an authenticated GET request to /wp-json/dokan/v1/settings with a user-controlled key referencing a target vendor's ID to retrieve their store settings, including payment details (PayPal email, bank account, IBAN, SWIFT).
  4. Modify payment settings: Send an authenticated PUT or POST request to /wp-json/dokan/v1/settings with the target vendor's ID and a modified paypal_email field set to an attacker-controlled address.
  5. Collect payouts: Wait for the marketplace to process payouts; funds destined for the victim vendor will be redirected to the attacker's PayPal account (Wordfence, Feedly).

Indicators of compromise

  • Network: Unusual authenticated REST API requests to /wp-json/dokan/v1/settings from customer-level accounts, especially GET or PUT requests referencing vendor IDs that do not belong to the authenticated user; repeated API calls to this endpoint from a single IP or user account in a short timeframe.
  • Logs: WordPress access logs showing GET or POST /wp-json/dokan/v1/settings requests from non-vendor user accounts; authentication logs showing customer accounts accessing vendor-specific API endpoints.
  • Application: Unexpected changes to vendor PayPal email addresses, bank account details, or other payment settings in the Dokan vendor management dashboard; vendor complaints about missing payouts or unauthorized changes to their store settings.

Mitigation and workarounds

Administrators should upgrade the Dokan plugin beyond version 4.2.4 as soon as a patched release is available; the fix was committed to the plugin repository in changeset 3432750 (WordPress Changeset). As an interim measure, restrict access to the /wp-json/dokan/v1/settings REST API endpoint at the network or web server level (e.g., via WAF rules or .htaccess) to limit exposure. Marketplace operators should also audit recent changes to vendor payment settings and monitor for unauthorized modifications to PayPal email addresses or bank account details (Feedly).

Community reactions

Wordfence, the reporting CNA, published a threat intelligence entry covering the vulnerability and included it in their weekly WordPress vulnerability report for January 19–25, 2026 (Wordfence Weekly Report). The vulnerability was also referenced in the CISA vulnerability bulletin for the week of January 19, 2026 (CISA Bulletin). Social media activity was limited to automated CVE notification accounts on Mastodon and Bluesky, with no significant researcher commentary or broader community discussion observed.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management