What is CVE-2026-16565?
CVE-2026-16565 is a vulnerability in the 'Dokan: AI Powered WooCommerce Multivendor Marketplace Solution' WordPress plugin before version 5.0.9. It fails to verify product ownership on REST write endpoints, enabling vendor accounts to modify product attributes and default attributes of other vendors' products. Users must update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-16565: 'Dokan: AI Powered WooCommerce Multivendor Marketplace Solution' WordPress plagininin 5.0.9-dan əvvəlki versiyalarında aşkar edilib. Bu boşluq satıcı hesabı olan istifadəçilərə REST yazma endpointləri vasitəsilə digər satıcıların məhsul atributlarını dəyişməyə imkan verir. Tətbiq sahibləri plaqini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which WordPress plugin does CVE-2026-16565 affect?
This vulnerability affects the 'Dokan: AI Powered WooCommerce Multivendor Marketplace Solution' plugin before version 5.0.9.
What can an authenticated vendor do by exploiting CVE-2026-16565?
A user with a vendor account can modify product attributes of other vendors' products via REST write endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.