Time-Based SQL Injection in Dokan Pro Plugin for WordPress
CVE-2026-12077
7.5HIGH
What is CVE-2026-12077?
The Dokan Pro plugin for WordPress is subject to a time-based SQL injection vulnerability that affects all versions up to and including 5.0.4. The issue arises from insufficient escaping of the user-supplied 'latitude' and 'longitude' parameters and a lack of adequate preparation in the SQL query. This flaw allows unauthenticated attackers to manipulate existing SQL queries, enabling them to potentially extract sensitive data from the database, which poses a significant risk to WordPress site security.
Affected Version(s)
Dokan Pro 0 <= 5.0.4