CVE-2026-16564
Received Received - Intake

Dokan Plugin Bulk Order Status Modification Vulnerability

Vulnerability report for CVE-2026-16564, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpdev dokan to 5.0.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Dokan WordPress plugin, which is used for creating multi-vendor marketplaces. The flaw allows vendors to change the status of any WooCommerce order on the site without verifying ownership. This means a vendor could modify orders belonging to other vendors or customers, potentially causing confusion or fraud.

Detection Guidance

Check for unauthorized bulk order-status changes in WooCommerce logs. Review REST API requests to the affected endpoint. Look for vendor accounts performing actions outside their assigned orders.

Impact Analysis

If you are a vendor using this plugin, an attacker with a vendor account could alter your orders, leading to financial loss or reputational damage. If you are a customer, your order status could be changed without your knowledge, affecting your purchases. Store owners may face operational disruptions or trust issues.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized access to personal or sensitive order data. GDPR requires protecting personal data, and HIPAA mandates securing health-related transactions. Unauthorized order changes may violate these regulations.

Mitigation Strategies

Update the Dokan plugin to version 5.0.9 or later immediately. Restrict vendor permissions to prevent bulk order modifications. Monitor order status changes for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16564. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart