Time-Based SQL Injection in Dokan Pro Plugin for WordPress
CVE-2026-12079
6.5MEDIUM
What is CVE-2026-12079?
The Dokan Pro plugin for WordPress is susceptible to time-based SQL Injection attacks via the 'orderby' parameter. This vulnerability exists across all versions up to and including 5.0.4, resulting from inadequate escaping of user-supplied inputs and insufficient preparation of the SQL query. Authenticated attackers with Subscriber-level access or higher can exploit this flaw to inject additional SQL queries into existing ones, potentially extracting sensitive information from the database.
Affected Version(s)
Dokan Pro 0 <= 5.0.4