---
id: CVE-2026-16574
title: >-
  The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  WordPress
  plugin before 5.0.11 does not verify that a downloadable product belongs to
  the requesting vendor before granting download permissions through one of its
  order…
summary: >-
  The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  WordPress
  plugin before 5.0.11 does not verify that a downloadable product belongs to
  the requesting vendor before granting download permissions through one of its
  order…
severity: none
published: '2026-08-08'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16574'
references:
  - url: 'https://wpscan.com/vulnerability/b38dc6a4-a590-402f-88e1-3624a22c7348/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.0023
epssPercentile: 0.123
ingestedAt: '2026-08-09T03:32:40.399Z'
---

## Overview

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
