Zero Day Monitor
ZDM
Dashboard
Vulnerabilities
Trending
Zero-Days
News
About
Login
← Back to list
8.8
CVE-2026-49780
dokan · dokan
WordPress Dokan plugin <= 5.0.2 - Privilege Escalation vulnerability
Description
Customer Privilege Escalation in Dokan <= 5.0.2 versions.
Affected Products
Vendor
Product
Versions
dokan
dokan
n/a
References
https://patchstack.com/database/wordpress/plugin/dokan-lite/vulnerability/wordpress-dokan-plugin-5-0-2-privilege-escalation-vulnerability?_s_id=cve
(vdb-entry)
Related News (1 articles)
Tier C
VulDB
11d ago
CVE-2026-49780 | Dokan Plugin up to 5.0.2 on WordPress privileges assignment
→ No new info (linked only)
CVSS 3.1
8.8
HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV
❌ No
Actively exploited
❌ No
CWE
CWE-266
Published
Jun 15, 2026
Last enriched
12d ago
Trending Score
7
Source articles
1
Independent
1
Info Completeness
5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack
Community Vote
0
Login to vote
0 upvotes
0 downvotes
No votes yet
Related CVEs (5)
CRITICAL
CVE-2026-56033
EXP
WordPress Dokan Pro plugin <= 5.0.4 - Privilege Escalation vulnerability
Trending: 54
HIGH
CVE-2026-11987
EXP
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter
Trending: 43
HIGH
CVE-2026-11783
EXP
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU
Trending: 43
MEDIUM
CVE-2026-10023
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers
Trending: 6
MEDIUM
CVE-2026-3504
EXP
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API Endpoint
Pin to Dashboard
Verification
State:
verified
Confidence:
100%
Vulnerability Timeline
CVE Published
Jun 15, 2026
Discovered by ZDM
Jun 16, 2026