What is CVE-2026-16574?
This vulnerability exists in the 'Dokan: AI Powered WooCommerce Multivendor Marketplace Solution' WordPress plugin before version 5.0.11. It allows an authenticated vendor to grant download permissions through one of its order REST endpoints for a downloadable product that does not belong to them. Users are advised to update the plugin to the latest version.
Azərbaycanca: Bu zəiflik Dokan: AI Powered WooCommerce Multivendor Marketplace Solution adlı WordPress plaginində tapılıb (5.0.11 versiyasına qədər). Bu, sifariş REST endpointlərindən birində autentifikasiya olunmuş vendor-a məxsus olmayan yüklənə bilən məhsulu öz istifadəçilərinə icazə vermək imkanı yaradır. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What does the CVE-2026-16574 vulnerability in the 'Dokan: AI Powered WooCommerce Multivendor Marketplace Solution' plugin allow an authenticated vendor to do?
This vulnerability allows an authenticated vendor to grant download permissions through one of its order REST endpoints for a downloadable product that does not belong to them.
Which versions of the Dokan plugin for WordPress are affected by CVE-2026-16574?
The vulnerability exists in the plugin up to version 5.0.11.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.