Known Vulnerabilities for Dokan Pro by Dokan Multivendor Plugin
Listed below are 10 of the newest known vulnerabilities associated with "Dokan Pro" by "Dokan Multivendor Plugin".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65495 json | Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65494 json | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65493 json | Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65492 json | Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-57706 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-56033 json | Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions. | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-49780 json | Customer Privilege Escalation in Dokan <= 5.0.2 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-12224 json | The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all version... | Not Provided | 2026-07-01 | 2026-07-01 |
| CVE-2026-12079 json | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions ... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-12077 json | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameter... | Not Provided | 2026-06-25 | 2026-06-29 |