PT-2026-54510 · WordPress · Dokan Pro

·

CVE-2026-12224

·

Published

2026-07-01

·

Updated

2026-07-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dokan Pro versions prior to 5.0.5
Description The plugin contains a privilege escalation flaw within the 'update capabilities' REST endpoint. The update capabilities() REST handler fails to implement allowlist validation when processing capability strings from the request body, passing them directly to the WP User::add cap() function. This allows authenticated attackers with Vendor-level access or higher, on sites where the Vendor Staff module is active, to assign arbitrary WordPress capabilities, such as administrator privileges, to any vendor staff account, potentially resulting in a complete site takeover.
Recommendations Update to version 5.0.5 or later. Restrict access to the 'update capabilities' REST endpoint to minimize the risk of exploitation.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12224

Affected Products

Dokan Pro