← Back to search

CVE-2026-8761

8.8 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows authenticated attackers with Vendor/Seller-level access to read, modify, or delete any WordPress user, including administrators, via REST API requests. This is due to a missing authorization check in the Dokan plugin's CustomersController.
Exploitability
Exploitation is relatively straightforward for attackers with Vendor/Seller-level access. Precondition is having an account with at least Vendor/Seller-level permissions.
Blast radius
If exploited, this vulnerability could result in full site takeover, as attackers can modify or delete administrators' records.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the Dokan plugin or upgrade to version 5.0.2 or later.
auth-bypasswebwp

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the `/dokan/v1/customers/` namespace and replaces WooCommerce's native `manage_woocommerce` capability check with a vendor-only check that inspects the **requesting** user's role and never validates the **target** user. This makes it possible for authenticated attackers with Vendor/Seller-level access and above to read, modify, or delete any WordPress user — including administrators — via `GET`/`PUT`/`DELETE` requests against `/wp-json/dokan/v1/customers/{id}`. Setting the `password` parameter on an administrator's record yields a full site takeover.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-862

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.