PT-2026-54510 · WordPress · Dokan Pro
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dokan Pro versions prior to 5.0.5
Description
The plugin contains a privilege escalation flaw within the 'update capabilities' REST endpoint. The
update capabilities() REST handler fails to implement allowlist validation when processing capability strings from the request body, passing them directly to the WP User::add cap() function. This allows authenticated attackers with Vendor-level access or higher, on sites where the Vendor Staff module is active, to assign arbitrary WordPress capabilities, such as administrator privileges, to any vendor staff account, potentially resulting in a complete site takeover.Recommendations
Update to version 5.0.5 or later.
Restrict access to the 'update capabilities' REST endpoint to minimize the risk of exploitation.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dokan Pro