PT-2026-67116 · Undefined · Undefined

·

CVE-2026-16564

·

Published

2026-08-03

·

Updated

2026-08-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-16564

Affected Products

Undefined