CVE-2026-16574
Last modified
CVE-2026-16574 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution | < 5.0.11 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-16574?
How severe is CVE-2026-16574?
How do I fix CVE-2026-16574?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-16563The Academy LMS WordPress plugin before 3.8.3 does not verif…6.5
- CVE-2026-16564The Dokan: AI Powered WooCommerce Multivendor Marketplace So…4.3
- CVE-2026-16565The Dokan: AI Powered WooCommerce Multivendor Marketplace So…4.3
- CVE-2026-1657The EventPrime plugin for WordPress is vulnerable to unautho…5.3
- CVE-2026-16572The LogMyTrip WordPress plugin through 1.9 does not sanitize…8.6
- CVE-2026-16573The Bit Form WordPress plugin before 3.2.0 does not sanitiz…7.5
- CVE-2026-16578The Admin Safety Guard — Login Security, Limit Logins, 2FA &…7.5
- CVE-2026-1658User Interface (UI) Misrepresentation of Critical Informatio…5.3
- CVE-2026-16581In igloohome Smart Lock Mobile App versions 3.2.3 and prior,…6.9
- CVE-2026-16583The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cook…6.1
- CVE-2026-16584Improper handling of an initialization failure in AWS API MC…7.3
- CVE-2026-16585The Better Messages – Chat Rooms, Group Chat, Private Messag…7.2
Are you affected by CVE-2026-16574?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
