What is CVE-2026-16564?
CVE-2026-16564 exists in the "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution" WordPress plugin before version 5.0.9. It fails to verify order ownership on a REST endpoint handling bulk order-status changes, allowing users with vendor accounts to modify any WooCommerce order status. Update the plugin immediately to the latest version.
Azərbaycanca: CVE-2026-16564 boşluğu "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution" WordPress plaginində 5.0.9 versiyasından əvvəl mövcuddur. REST endpoint-də sifariş sahibliyini yoxlamadığı üçün vendor hesabı olan istifadəçilər bazardakı istənilən WooCommerce sifarişinin statusunu dəyişdirə bilər. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-16564?
It affects the "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution" plugin.
What can a user with a vendor account do by exploiting this vulnerability?
They can modify the status of any WooCommerce order in the marketplace.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.