PT-2026-52191 · WordPress · Dokan Pro

CVE-2026-12077

·

Published

2026-06-25

·

Updated

2026-06-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dokan Pro versions prior to 5.0.5
Description The Dokan Pro plugin for WordPress contains a time-based SQL Injection flaw. This issue occurs because user-supplied parameters are not sufficiently escaped and the SQL query is not properly prepared. Unauthenticated attackers can exploit this by appending additional SQL queries to existing ones to extract sensitive information from the database via the latitude and longitude parameters.
Recommendations Update Dokan Pro to a version newer than 5.0.4. As a temporary mitigation, restrict or filter the use of the latitude and longitude parameters.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12077

Affected Products

Dokan Pro