Improper User Capability Checks in Dokan WooCommerce Plugin
CVE-2026-16576

Currently unrated

Key Information:

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-16576?

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress versions prior to 5.0.14 contains a flaw in its admin REST API routes. Specifically, it fails to accurately verify user capabilities, allowing unauthorized users—such as Shop Managers—access to install and activate arbitrary versions of the Dokan plugin. This oversight can lead to potential security risks, as it may permit untrusted actions within the WooCommerce environment, highlighting the need for robust capability checks to safeguard the marketplace.

Affected Version(s)

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution 0 < 5.0.14

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khaled Alenazi (Nxploited)
WPScan
.