« Volver al listado

Dokan

Dokan PRO: vulnerabilidades y CVE

Dokan PRO tiene 6 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses6
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-65495Alta (7.5)0.43%—23 jul 2026
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
CVE-2026-65493Alta (7.5)0.40%—23 jul 2026
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
CVE-2026-56033Crítica (9.8)0.48%—26 jun 2026
Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.
CVE-2026-12079Media (6.5)0.38%—25 jun 2026
The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack…
CVE-2026-12077Alta (7.5)0.46%—25 jun 2026
The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to insufficient escaping on the user…
CVE-2025-39497Media (6.5)0.15%—5 ene 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro allows Stored XSS.This issue affects Dokan Pro: from n/a through 3.14.5.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1005 Data from Local System1
  3. T1059 Command and Scripting Interpreter1
  4. T1068 Exploitation for Privilege Escalation1
  5. T1078 Valid Accounts1
  6. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Dokan