Product Ownership Verification Flaw in Dokan WooCommerce Multivendor Solution
CVE-2026-16565
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 August 2026
Badges
What is CVE-2026-16565?
The Dokan WooCommerce Multivendor Marketplace Solution plugin prior to version 5.0.9 is susceptible to an authorization bypass vulnerability. This flaw occurs due to the plugin's failure to verify product ownership on its product-attribute REST write endpoints. As a result, users with Dokan vendor accounts can potentially modify product attributes and default settings of other vendors' products within the marketplace. This compromise can disrupt normal operations and lead to unauthorized changes across the shared platform, highlighting the importance of robust ownership verification measures in software development.
Affected Version(s)
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution 0 < 5.0.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.