What is CVE-2026-8761?
This vulnerability affects the Dokan plugin for WordPress in all versions up to and including 5.0.1. Due to a missing authorization check in the `CustomersController.php` REST controller, it allows Privilege Escalation via re-registered WooCommerce customer CRUD routes. Users are advised to update the plugin to the latest version immediately.
Azərbaycanca: Bu zəiflik WordPress üçün Dokan plugin-in 5.0.1-ə qədər olan bütün versiyalarını əhatə edir. `CustomersController.php` faylında authorization yoxlanışının olmaması səbəbindən REST API vasitəsilə imtiyazların yüksəldilməsi (Privilege Escalation) mümkündür. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: WooCommerce
FAQ2
Which versions of the Dokan plugin for WordPress are affected by CVE-2026-8761?
All versions of the Dokan plugin up to and including 5.0.1 are affected by this vulnerability.
What is the root cause of the CVE-2026-8761 vulnerability?
The root cause is a missing authorization check in the `CustomersController.php` REST controller.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.