PT-2024-11563 · WordPress · Dokan

Veshraj Ghimire

·

Published

2024-01-16

·

Updated

2026-02-24

·

CVE-2022-3194

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dokan WordPress plugin versions prior to 3.6.4
Description The issue allows vendors to inject arbitrary javascript in product reviews, potentially leading to stored XSS attacks against other users, including site administrators.
Recommendations For versions prior to 3.6.4, update to version 3.6.4 or later to resolve the issue. As a temporary workaround, consider disabling the product review feature until a patch is available. Restrict access to product reviews to minimize the risk of exploitation. Avoid allowing vendors to inject arbitrary javascript in product reviews until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3194

Affected Products

Dokan