Sceawere
Vulnerability Detail
CVE-2026-107694UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dokan Improper Access Control Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.7
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
- Attack Type
- CWE-200 Information Exposure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.2.0 does not verify that the vendor a commission calculation is requested for is the requesting vendor, allowing vendors to disclose the commission rate and fixed fee the marketplace administrator configured for other vendors.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.7",
"pubDate": "2026-10-11T07:17:23.187Z",
"pubdate": "2026-10-11T07:17:23.187Z",
"executiveSummary": "The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin prior to version 5.2.0 contains an Insecure Direct Object Reference (IDOR) vulnerability related to commission calculation requests.\nThe vulnerability arises from a lack of server-side authorization checks, specifically failing to validate that the authenticated vendor requesting commission data is the owner of the requested data.\nThis flaw allows a malicious vendor to query and disclose the commission rates and fixed fee configurations assigned to other vendors within the marketplace.\nThe impact is limited to unauthorized information disclosure of internal business logic and commission structures.\nExploitation requires the attacker to possess a valid vendor account on the target WordPress installation.\nSuccessful exploitation allows attackers to gain competitive intelligence regarding how other vendors are compensated, potentially compromising the administrative privacy of the marketplace's financial model.",
"technicalDetails": "The root cause of this vulnerability is a broken access control mechanism within the commission calculation logic of the Dokan plugin. The plugin fails to perform a rigorous security check to verify the identity of the user requesting commission configuration details against the account associated with the specific vendor ID provided in the request.\nIn a secure implementation, the application should cross-reference the current authenticated user's session ID with the owner ID of the requested commission record. Because this validation is absent, the backend API endpoint blindly trusts the vendor ID parameter provided by the client, allowing for the manipulation of requests to access unauthorized resources.\nThe attack flow proceeds as follows: 1) A logged-in vendor identifies the API endpoint used for fetching commission calculations. 2) The attacker intercepts or crafts a request specifying a different, arbitrary vendor ID in the query parameters. 3) The server processes the request without confirming authorization, retrieving the commission rate and fixed fee configuration associated with the target vendor ID. 4) The server returns this sensitive information in the response, which the attacker then parses.\nThe vulnerability is persistent across all versions of the Dokan plugin prior to 5.2.0. The affected component is the internal API handler responsible for managing vendor-specific commission logic. Because this is a logic flaw rather than a memory corruption or injection vulnerability, it does not require complex payloads; it simply requires the attacker to have valid vendor-level privileges, which is standard for any user registered as a vendor on the platform.\nFrom a post-exploitation perspective, the attacker gains insight into the platform's proprietary commission structures. This facilitates unauthorized access to business intelligence, which could be leveraged to gain a competitive advantage, reveal disparate treatment among vendors, or assist in further reconnaissance of the marketplace’s administrative configurations.\nThe vulnerability is fully accessible via the web application interface as long as the attacker has active authentication tokens corresponding to a vendor account, making the network exposure equal to the reach of the site's front-end or back-end API accessibility."
}