Improper User Capability Checks in Dokan WooCommerce Plugin
CVE-2026-16576
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 August 2026
Badges
What is CVE-2026-16576?
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress versions prior to 5.0.14 contains a flaw in its admin REST API routes. Specifically, it fails to accurately verify user capabilities, allowing unauthorized users—such as Shop Managers—access to install and activate arbitrary versions of the Dokan plugin. This oversight can lead to potential security risks, as it may permit untrusted actions within the WooCommerce environment, highlighting the need for robust capability checks to safeguard the marketplace.
Affected Version(s)
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution 0 < 5.0.14
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.