Data Exposure Vulnerability in Dokan Pro Plugin for WordPress
CVE-2025-12809
5.3MEDIUM
What is CVE-2025-12809?
The Dokan Pro plugin for WordPress is subject to a security issue due to inadequate capability checks on the /dokan/v1/wholesale/register REST API endpoint. This vulnerability allows unauthenticated attackers to gain unauthorized access to sensitive user information. By supplying a user ID, attackers can enumerate user-related data, including email addresses, usernames, display names, user roles, and registration dates. As a result, website owners using this plugin need to be aware of this risk and implement measures to secure their WordPress site.
Affected Version(s)
Dokan Pro * <= 4.1.3