WordPress · Dokan · CVE-2026-11783
**Name of the Vulnerable Software and Affected Versions**
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution versions prior to 5.0.5
**Description**
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Authenticated attackers with custom-level access or higher can inject arbitrary web scripts into pages. These scripts execute when a user accesses the affected page, as the store search widget inserts an unescaped AJAX response HTML into the Document Object Model (DOM) using the jQuery `.html()` method. The malicious payload is delivered to site visitors, including unauthenticated users, via the product SKU.
**Recommendations**
Update Dokan: AI Powered WooCommerce Multivendor Marketplace Solution to version 5.0.5 or later.