NONE · 0

CVE-2026-16574

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download...

Vulnerability Description

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.

References

FAQ

What is CVE-2026-16574?

CVE-2026-16574 is a documented vulnerability. The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download...

How severe is CVE-2026-16574?

CVSS scoring is not yet available for CVE-2026-16574. Check NVD for updates.

Is there a patch for CVE-2026-16574?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.