---
id: CVE-2026-107694
title: >-
  The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  WordPress
  plugin before 5.2.0 does not verify that the vendor a commission calculation
  is requested for is the requesting vendor, allowing vendors to disclose the
  commis…
summary: >-
  The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  WordPress
  plugin before 5.2.0 does not verify that the vendor a commission calculation
  is requested for is the requesting vendor, allowing vendors to disclose the
  commis…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
published: '2026-10-11'
updated: '2026-10-11'
sourceUpdated: '2026-10-11T12:16:52.630'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107694'
references:
  - url: 'https://wpscan.com/vulnerability/ddce69ff-5325-432c-9f3a-66ec9a19bcb4/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-11T08:44:24.711Z'
---

## Overview

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  WordPress plugin before 5.2.0 does not verify that the vendor a commission calculation is requested for is the requesting vendor, allowing vendors to disclose the commission rate and fixed fee the marketplace administrator configured for other vendors.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
