The Dokan plugin for WordPress contains a vulnerability in versions up to and including 3.7.19. If you have this version installed, then an attacker with Shop Manager privileges or higher could inject malicious code into the plugin. This could allow them to delete files, access sensitive information, and even execute code. It is not known if a “Pop Chain” is present which could increase the severity of the attack.