dokan pro <= 4.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure

2025-12-15 16:39
Ahmed Rayen Ayari

Strategic Overview

Status
Patched in 4.2.0
Affected PluginDokan Pro
Affected Version<= 4.1.3
CVSS5.3Medium
CVECVE-2025-12809
View all Dokan Pro vulnerabilities

Vulnerability Overview

The Dokan Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `/dokan/v1/wholesale/register` REST API endpoint in all versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to enumerate users and retrieve their email addresses via the REST API by providing a user ID, along with other information such as usernames, display names, user roles, and registration dates.

Technical Analysis

REMEDIATION: Update to version 4.2.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C