CVE-2026-24359 HIGH

CVE-2026-24359: WordPress Dokan plugin <= 4.2.4 - Broken Authentication vulnerability

Vendor Dokan, Inc.
Product Dokan
Weakness CWE-288
Published March 25, 2026
Last update April 28, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4.

Explanation of Vulnerability in Simple Terms

02Summary

Dokan versions up to 4.2.4 contain an authentication bypass vulnerability. An attacker with low-level user privileges can gain unauthorized access to sensitive data and modify site content without proper authorization. The vulnerability requires network access but no user interaction, making it exploitable remotely by authenticated users.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify content, and disrupt site availability with a low-privilege user account.

Potential impact on your site

04Site Impact

Authenticated users can escalate privileges to access admin functions, read private data, and modify or delete content.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site; no user interaction required.

Key dates

06Disclosure timeline

March 25, 2026 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE