CVE-2023-34382 MEDIUM

CVE-2023-34382: WordPress Dokan Plugin <= 3.7.19 is vulnerable to PHP Object Injection

Vendor Wedevs
Product Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
Weakness CWE-502 · Unsafe deserialization
Published December 19, 2023
Last update April 28, 2026

CVSS base score

4.4/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.19.

Explanation of Vulnerability in Simple Terms

02Summary

Dokan versions up to 3.7.19 contain a deserialization vulnerability in how the plugin processes untrusted data. An authenticated admin with high privileges can craft a malicious request that causes the plugin to deserialize and execute arbitrary code. The vulnerability requires high attack complexity and affects data confidentiality and integrity across the site.

What an attacker can do

03Attacker Capabilities

Read or modify sensitive site data by sending a specially crafted request.

Potential impact on your site

04Site Impact

A compromised admin account could leak customer data or alter marketplace settings without detection.

Conditions required to exploit

05Prerequisites

Admin-level access to the WordPress site; attacker must be authenticated with high privileges.

Key dates

06Disclosure timeline

December 19, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE