Dokan Pro
cpe:2.3:a:dokan:dokan_pro_plugin:*:*:*:*:wordpress:*:*
- <= 4.0.5
A privilege escalation vulnerability has been identified in the Dokan Pro plugin for WordPress, affecting all versions through 4.0.5. The issue arises because the plugin fails to properly verify a user's identity before allowing password changes during staff password resets. This flaw enables authenticated attackers with vendor-level access or higher to escalate their privileges to that of a staff member. Once elevated, they can change passwords for any user, including administrators, to gain unauthorized access to their accounts. By default, the plugin permits customers to become vendors.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling attackers to gain staff-level access and manipulate user accounts, including those of administrators.
Users can update to version 4.0.6 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.