CVE-2026-16574Disclosure

LOWCVSS 5.4 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-08: 4Technical Details · 2026-08-08: 308-08
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-16574 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesti… https://www.cve.org/CVERecord?id=CVE-2026-16574 ----- Traducción: CVE-2026-16574 El … http://infoflow.cloud`

    Post summary

    The tweet announces a new CVE (CVE‑2026‑16574) for the Dokan WordPress plugin, noting a verification flaw in versions before 5.0.11, without providing PoC, exploit, or patch information.

    0000048
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-16574 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesti… https://www.cve.org/CVERecord?id=CVE-2026-16574

    Post summary

    CVE-2026-16574 highlights an input validation flaw in the Dokan WordPress plugin prior to version 5.0.11, with no PoC, exploit, or patch information disclosed.

    000001.1K
    57.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🛒 Dokan marketplace flaw crosses vendor boundaries CVE-2026-16574 affects the AI-powered Dokan WooCommerce Multivendor Marketplace before version 5.0.11. An authenticated vendor could potentially grant customers access to another vendor's paid downloadable products. 🔎 Source: WPScan / CVE #WooCommerce #WordPress #CVE #EcommerceSecurity #CyberSecurity

    Post summary

    The post announces CVE-2026-16574, a flaw in Dokan WooCommerce that allows an authenticated vendor to bypass vendor boundaries and access other vendors’ paid downloadable products, affecting versions prior to 5.0.11.

    0000037
    34 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-16574 The Dokan https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-16574

    Post summary

    The message simply lists CVE-2026-16574 for the Dokan project and provides a link to a Vulmon vulnerability details page, offering no additional context on exploitation, mitigation, or technical specifics.

    00000127
    4.1K followersView on X

Explore more