CVE-2026-16577Disclosure

LOWCVSS 2.7 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-21: 2Technical Details · 2026-08-21: 108-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-16577 Dokan WordPress Plugin Allows Vendors to Clear Debt Through Arbitrary Credit https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-16577

    Post summary

    The entry describes a newly disclosed CVE in the Dokan WordPress Plugin that enables vendors to clear debt via arbitrary credit manipulation, with no evidence of active exploitation, PoC, or patch offered.

    00010102
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-16577 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vend… https://www.cve.org/CVERecord?id=CVE-2026-16577

    Post summary

    The text announces a vulnerability in the Dokan WooCommerce plugin that fails to validate client-supplied payment amounts, but provides no further details or evidence of exploitation.

    000001.0K
    58.0K followersView on X

Explore more