在 Dokan:AI 驱动的 WooCommerce 多商户市场解决方案 WordPress 插件中,5.0.14 版本之前存在一个漏洞。该漏洞未限制通过其未经身份验证的商店 REST 端点返回的每个商户佣金配置的访问权限,导致任何未经身份验证的用户都可以披露商户的佣金类型。此外,当配置基于类别的佣金时,还可以获取每个类别及默认佣金费率。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution | < 5.0.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution | 0 ~ 5.0.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19848 | 6.5 MEDIUM | ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution via Display Name |
| CVE-2026-17559 | 5.3 MEDIUM | Content Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disclosure via RE |
| CVE-2026-16650 | 5.3 MEDIUM | Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webh |
| CVE-2026-15150 | 5.3 MEDIUM | myCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verificati |
| CVE-2026-15046 | 4.2 MEDIUM | LitExtension: Store to WooCommerce Migration <= 1.2.5 - Connector Token Takeover via CSRF |
| CVE-2026-18356 | 3.7 LOW | Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Variant and Acco |
| CVE-2026-13176 | 2.7 LOW | Eventin < 4.1.21 - Contributor+ Server-Side Request Forgery |
| CVE-2026-13736 | NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII D | |
| CVE-2025-15671 | Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter | |
| CVE-2026-14325 | Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via dr | |
| CVE-2026-14601 | Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter | |
| CVE-2026-16576 | Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API | |
| CVE-2026-16962 | Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation | |
| CVE-2026-19085 | Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure | |
| CVE-2026-19435 | Copy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Password Disclosure | |
| CVE-2026-18781 | Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via | |
| CVE-2026-16959 | Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector | |
| CVE-2026-16577 | Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount | |
| CVE-2026-75796 | AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP |
No comments yet