CVE-2026-16574: CWE-639 Authorization Bypass Through User-Controlled Key in Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.
AI Analysis
Technical Summary
CVE-2026-16574 is an authorization bypass vulnerability (CWE-639) in the Dokan WordPress plugin for WooCommerce multivendor marketplaces. Versions prior to 5.0.11 fail to verify ownership of downloadable products when processing download permission requests through an order REST API endpoint. This allows an authenticated vendor to improperly grant download access to paid files owned by other vendors, potentially leading to unauthorized distribution of paid content.
Potential Impact
The vulnerability allows authenticated vendors to grant unauthorized download access to paid downloadable products belonging to other vendors. This could result in revenue loss due to unauthorized free distribution of paid content. The confidentiality and integrity of vendor product access controls are compromised. There is no indication of impact on availability. The CVSS 3.1 base score is 5.4 (medium severity), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, and limited confidentiality and integrity impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch link is provided, users should monitor the vendor's announcements for updates. Until a fix is available, restrict vendor permissions and closely audit download access requests to mitigate unauthorized access risks.
CVE-2026-16574: CWE-639 Authorization Bypass Through User-Controlled Key in Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
Description
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.
CVSS v3.1
Score 5.4medium
Affected software
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16574 is an authorization bypass vulnerability (CWE-639) in the Dokan WordPress plugin for WooCommerce multivendor marketplaces. Versions prior to 5.0.11 fail to verify ownership of downloadable products when processing download permission requests through an order REST API endpoint. This allows an authenticated vendor to improperly grant download access to paid files owned by other vendors, potentially leading to unauthorized distribution of paid content.
Potential Impact
The vulnerability allows authenticated vendors to grant unauthorized download access to paid downloadable products belonging to other vendors. This could result in revenue loss due to unauthorized free distribution of paid content. The confidentiality and integrity of vendor product access controls are compromised. There is no indication of impact on availability. The CVSS 3.1 base score is 5.4 (medium severity), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, and limited confidentiality and integrity impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch link is provided, users should monitor the vendor's announcements for updates. Until a fix is available, restrict vendor permissions and closely audit download access requests to mitigate unauthorized access risks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-22T13:01:02.571Z
- State
- PUBLISHED
Threat ID: 6a76cc2abf8831d539114718
Added to database: 08/08/2026, 06:26:50 UTC
Last enriched: 08/15/2026, 14:59:47 UTC
Last updated: 09/21/2026, 22:01:32 UTC
Views: 59
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.