The Dokan plugin for WordPress has a security vulnerability for versions up to and including 3.0.8. This vulnerability is called Cross-Site Request Forgery and happens when the handle_order_export() function does not have enough security measures in place. This means that unauthenticated attackers can send a fake request and trick an administrator into performing an action such as clicking a link.