
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16565 is an Insecure Direct Object Reference (IDOR) / authorization bypass vulnerability in the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin. It affects all versions before 5.0.9 and allows any authenticated Dokan vendor to modify product attributes and default attributes belonging to other vendors on the same marketplace. The vulnerability was publicly disclosed on July 24, 2026, and assigned a CVSS score of 4.3 (Medium) (WPScan, GitHub Advisory).
The root cause is a missing product ownership verification on the plugin's product-attribute REST API write endpoints (CWE-639: Authorization Bypass Through User-Controlled Key), classified under OWASP Top 10 A5: Broken Access Control (WPScan). An attacker with a valid Dokan vendor account can send crafted REST API requests targeting another vendor's product ID to modify that product's attributes or default attributes without any ownership check. The precondition for exploitation is possession of a legitimate Dokan vendor account on the affected marketplace; unauthenticated users cannot exploit this vulnerability. The original researcher is Sai Praneeth Koti, and a proof-of-concept was scheduled for public release on August 7, 2026, to allow time for patching (WPScan).
Successful exploitation allows a malicious vendor to tamper with competitors' product listings by modifying their attributes and default attributes, directly compromising marketplace integrity and potentially enabling sabotage of competing vendors' products. While this does not result in remote code execution or direct data exfiltration, it can cause reputational and financial harm to affected vendors and undermine customer trust in the marketplace platform. The impact is limited to the integrity of product data within the WooCommerce multivendor marketplace and does not affect system-level confidentiality or availability (WPScan, GitHub Advisory).
GET /wp-json/dokan/v1/products)./wp-json/dokan/v1/products/{product_id}/attributes or /wp-json/dokan/v1/products/{product_id}/default-attributes, including modified attribute data in the request body./wp-json/dokan/v1/products/{product_id}/attributes or /wp-json/dokan/v1/products/{product_id}/default-attributes where the requesting vendor's user ID does not match the product owner's ID.Update the Dokan plugin to version 5.0.9 or later, which introduces proper product ownership verification on the product-attribute REST API write endpoints (WPScan, GitHub Advisory). No official configuration-based workaround has been published; upgrading is the recommended and only confirmed remediation. Marketplace administrators should also audit recent product attribute changes for signs of unauthorized modification prior to patching.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."