Access violation vulnerability in Dokan Pro 4.0.5

The Dokan Pro plugin for WordPress has a security issue that can potentially allow unauthorized access to user accounts. This vulnerability affects all versions up to 4.0.5. The problem lies in the plugin’s lack of proper verification of a user’s identity when updating their password during a staff password reset. This means that attackers with vendor-level access or higher can exploit this vulnerability to gain the same privileges as a staff member and change user passwords, including those of administrators. This could potentially give them access to sensitive accounts. By default, the plugin allows customers to become vendors.

Detected in:

Dokan Pro open vulnerable versions: >= * <= 4.0.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.