The Dokan plugin for WordPress, up to and including version 3.6.5, has a security vulnerability which could allow unauthenticated attackers to take control of certain settings during the setup process. This is because the setup_wizard function does not have the correct validation in place to protect against Cross-Site Request Forgery. This means that attackers can create a link or other form of request that could be clicked on by a site administrator, allowing them to make changes to the settings on the site.