Plugin Vulnerability Hub
Plugin 10 known issues Latest disclosed May 01, 2026

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Vulnerabilities

Review known vulnerability records for the WordPress plugin Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy (`dokan-lite`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-3504, CVE-2026-24359 and CVE-2025-14977, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
10
High or Critical
5
Patch Coverage
100%
Last Updated
May 02, 2026
Related Security Guides

Use these guides while reviewing Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
10
1. Match the Package
Confirm the installed WordPress plugin slug is dokan-lite before acting on any CVE from this cluster.
2. Sort by Severity
Start with 5 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
10 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
10
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2022-3915
Dokan <= 3.7.5 - Unauthenticated SQL Injection
SQL Injection Versions up to 3.7.5 3.7.6 CVSS 9.8
CVE-2022-3194
Dokan <= 3.6.5 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions up to 3.6.5 3.6.6 CVSS 8.8
CVE-2025-14977
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amaz...
Vulnerability Versions up to 4.2.4 4.2.5 CVSS 8.1
CVE-2025-53425
Dokan <= 4.1.3 - Authenticated (Shop Manager+) Privilege Escalation
Privilege Escalation Versions up to 4.1.3 4.1.4 CVSS 7.2
CVE-2023-26525
Dokan <= 3.7.12 - Authenticated (Vendor+) SQL Injection
SQL Injection Versions up to 3.7.12 3.7.13 CVSS 7.2
CVE-2023-34382
Dokan <=3.7.19 - Authenticated(Shop Manager+) PHP Object Injection via create_dummy_...
Vulnerability Versions before 3.7.20 3.7.20 CVSS 6.6
CVE-2022-3194
Dokan <= 3.6.3 - Authenticated (Vendor+) Stored Cross-Site Scripting
Stored Cross-Site Scripting Versions up to 3.6.3 3.6.4 CVSS 5.5
CVE-2026-3504
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenti...
Sensitive Information Exposure Versions up to 4.3.1 4.3.2 CVSS 5.3
CVE-2022-3915 Critical 3.7.6
CVE-2022-3915 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy SQL Injection

Dokan <= 3.7.5 - Unauthenticated SQL Injection

CVE-2022-3194 High 3.6.6
CVE-2022-3194 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Cross-Site Request Forgery

Dokan <= 3.6.5 - Cross-Site Request Forgery

CVE-2025-14977 High 4.2.5
CVE-2025-14977 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Vulnerability

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure

CVE-2025-53425 High 4.1.4
CVE-2025-53425 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Privilege Escalation

Dokan <= 4.1.3 - Authenticated (Shop Manager+) Privilege Escalation

CVE-2023-26525 High 3.7.13
CVE-2023-26525 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy SQL Injection

Dokan <= 3.7.12 - Authenticated (Vendor+) SQL Injection

CVE-2023-34382 Medium 3.7.20
CVE-2023-34382 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Vulnerability

Dokan <=3.7.19 - Authenticated(Shop Manager+) PHP Object Injection via create_dummy_vendor

CVE-2022-3194 Medium 3.6.4
CVE-2022-3194 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Stored Cross-Site Scripting

Dokan <= 3.6.3 - Authenticated (Vendor+) Stored Cross-Site Scripting

CVE-2026-3504 Medium 4.3.2
CVE-2026-3504 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Sensitive Information Exposure

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API Endpoint

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
10 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 4 high severity findings.
Recent CVEs
CVE-2026-3504, CVE-2026-24359 and CVE-2025-14977
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

CVE-2025-14977 High Patch path listed

CVE-2025-14977: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up t...

Published
Jan 19, 2026
Patch Status
4.2.5
Known Vulnerabilities

Reports for Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-3504
CVE-2026-3504: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API Endpoint

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due to the 'prepare_reviews_for_r...

Published
May 01, 2026
Patched Release
4.3.2
Affected Versions
Versions up to 4.3.1
Next Step
Update to 4.3.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24359
CVE-2026-24359: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Missing Authorization

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.4. This makes it possible for...

Published
Mar 16, 2026
Patched Release
4.2.5
Affected Versions
Versions up to 4.2.4
Next Step
Update to 4.2.5 or newer if supported.
Plugin High Patched: Yes CVE-2025-14977
CVE-2025-14977: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to miss...

Published
Jan 19, 2026
Patched Release
4.2.5
Affected Versions
Versions up to 4.2.4
Next Step
Update to 4.2.5 or newer if supported.
Plugin High Patched: Yes CVE-2025-53425
CVE-2025-53425: Dokan <= 4.1.3 - Authenticated (Shop Manager+) Privilege Escalation

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Shop Manager-lev...

Published
Sep 20, 2025
Patched Release
4.1.4
Affected Versions
Versions up to 4.1.3
Next Step
Update to 4.1.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-34382
CVE-2023-34382: Dokan <=3.7.19 - Authenticated(Shop Manager+) PHP Object Injection via create_dummy_vendor

The Dokan plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7.19 via deserialization of untrusted input via the 'create_dummy_vendor' function called by the 'import' REST API endpoint. This allows authenticated attackers with Shop Mana...

Published
Jun 07, 2023
Patched Release
3.7.20
Affected Versions
Versions before 3.7.20
Next Step
Update to 3.7.20 or newer if supported.
Plugin High Patched: Yes CVE-2023-26525
CVE-2023-26525: Dokan <= 3.7.12 - Authenticated (Vendor+) SQL Injection

The Dokan plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and including, 3.7.12 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for aut...

Published
Mar 02, 2023
Patched Release
3.7.13
Affected Versions
Versions up to 3.7.12
Next Step
Update to 3.7.13 or newer if supported.
Plugin Critical Patched: Yes CVE-2022-3915
CVE-2022-3915: Dokan <= 3.7.5 - Unauthenticated SQL Injection

The Dokan plugin for WordPress is vulnerable to SQL Injection via the ‘user_ids’ parameter in versions up to, and including, 3.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query on an AJAX action that is av...

Published
Nov 21, 2022
Patched Release
3.7.6
Affected Versions
Versions up to 3.7.5
Next Step
Update to 3.7.6 or newer if supported.
Plugin High Patched: Yes CVE-2022-3194
CVE-2022-3194: Dokan <= 3.6.5 - Cross-Site Request Forgery

The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.5. This is due to missing or incorrect nonce validation on the setup_wizard function. This makes it possible for unauthenticated attackers to change settings in the se...

Published
Sep 28, 2022
Patched Release
3.6.6
Affected Versions
Versions up to 3.6.5
Next Step
Update to 3.6.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-3194
CVE-2022-3194: Dokan <= 3.6.3 - Authenticated (Vendor+) Stored Cross-Site Scripting

The Dokan plugin for WordPress is vulnerable to Stored Cross-Site Scripting via product reviews in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with vendor permissions and abov...

Published
Sep 13, 2022
Patched Release
3.6.4
Affected Versions
Versions up to 3.6.3
Next Step
Update to 3.6.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2020-36748
CVE-2020-36748: Dokan <= 3.0.8 - Cross-Site Request Forgery Bypass

The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers to trigger an order...

Published
Sep 16, 2020
Patched Release
3.0.9
Affected Versions
Versions before 3.0.9
Next Step
Update to 3.0.9 or newer if supported.