Dokan is a WordPress file-system abstraction plugin with a narrowly scoped but prominent footprint in e-commerce and marketplace deployments. Its vulnerability profile skews strongly toward critical-severity outcomes and frequently acquires public exploit code, with recurring weaknesses centered on SQL injection, cross-site scripting, cross-site request forgery, and unsafe deserialization that are characteristic of server-side web applications handling user input and plugin integration. Defenders should track this vendor's releases closely given the direct exposure in internet-facing WordPress instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dokan over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3922CRITICAL The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user sup | Jun 13, 2024 | 9.8 | 68 | NO | YES |
CVE-2023-34382HIGH Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – B | Dec 19, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-3915CRITICAL The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthentica | Dec 12, 2022 | 9.8 | 24 | NO | NO |
CVE-2023-26525HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your | Dec 20, 2023 | 8.1 | 23 | NO | NO |
CVE-2022-3194MEDIUM The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like si | Jan 16, 2024 | 5.4 | 19 | NO | NO |
CVE-2020-36748MEDIUM The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the hand | Jul 1, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dokan.
Media articles that mention a CVE ID that affects a product developed by Dokan — matched by CVE ID, not by vendor name.