PT-2026-50617 · Woocommerce · Dokan
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution versions prior to 5.0.4
Description
An Insecure Direct Object Reference exists due to missing ownership validation on a user-controlled order ID key. Authenticated attackers with custom vendor-level access or higher can exploit this by harvesting a valid nonce from their own dashboard order pages, such as '/dashboard/orders/?order id=OWN ORDER ID', and replaying it against a victim order ID. This allows the modification of arbitrary order statuses, injection of fake shipping tracking information, and the granting or revoking of downloadable-product permissions. Additionally, attackers can add controlled notes to any order, including customer-facing notes that trigger notification emails, or delete any order note or WordPress comment by ID regardless of ownership. The issue is present in the following AJAX handlers: 'change order status', 'add order note', 'delete order note', 'add shipping tracking info', 'grant access to download', and 'revoke access to download'.
Recommendations
Update to a version later than 5.0.3.
As a temporary workaround, restrict access to the 'change order status', 'add order note', 'delete order note', 'add shipping tracking info', 'grant access to download', and 'revoke access to download' AJAX handlers for vendor-level users.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dokan