PHP Object Injection Vulnerability in Dokan Pro by Xooting Solutions
CVE-2026-65493

7.5HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-65493?

The Dokan Pro plugin is susceptible to a PHP Object Injection vulnerability, which affects versions up to 5.0.2. This flaw allows attackers to exploit the PHP object serialization features inappropriately, posing significant risks to web application integrity and data security. It is crucial for users to upgrade to the latest version to mitigate potential threats.

Affected Version(s)

Dokan Pro <= 5.0.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Expatch | Patchstack Bug Bounty Program
.