CVE-2026-16576 PUBLISHED

Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API

Assigner: WPScan
Reserved: 22.07.2026 Published: 21.08.2026 Updated: 21.08.2026

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Managers to install and activate arbitrary Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 from WordPress.org.

Product Status

Vendor Unknown
Product Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
Versions Default: unaffected
  • affected from 0 to 5.0.14 (excl.)

Credits

  • Khaled Alenazi (Nxploited) finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE