PT-2026-50617 · Woocommerce · Dokan

·

CVE-2026-10023

·

Published

2026-06-18

·

Updated

2026-06-18

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dokan: AI Powered WooCommerce Multivendor Marketplace Solution versions prior to 5.0.4
Description An Insecure Direct Object Reference exists due to missing ownership validation on a user-controlled order ID key. Authenticated attackers with custom vendor-level access or higher can exploit this by harvesting a valid nonce from their own dashboard order pages, such as '/dashboard/orders/?order id=OWN ORDER ID', and replaying it against a victim order ID. This allows the modification of arbitrary order statuses, injection of fake shipping tracking information, and the granting or revoking of downloadable-product permissions. Additionally, attackers can add controlled notes to any order, including customer-facing notes that trigger notification emails, or delete any order note or WordPress comment by ID regardless of ownership. The issue is present in the following AJAX handlers: 'change order status', 'add order note', 'delete order note', 'add shipping tracking info', 'grant access to download', and 'revoke access to download'.
Recommendations Update to a version later than 5.0.3. As a temporary workaround, restrict access to the 'change order status', 'add order note', 'delete order note', 'add shipping tracking info', 'grant access to download', and 'revoke access to download' AJAX handlers for vendor-level users.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10023

Affected Products

Dokan