What the vulnerability does
01Description
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
Explanation of Vulnerability in Simple Terms
Dokan Pro versions up to 5.0.3 lack proper authorization checks, allowing unauthenticated attackers to disrupt the site's availability. The vulnerability requires no special access or user interaction—an attacker can send network requests to trigger a denial-of-service condition. Site administrators should update to a version newer than 5.0.3 as soon as possible.
What an attacker can do
Make the site unavailable or unresponsive by sending requests that consume server resources.
Potential impact on your site
Your Dokan marketplace may become slow or inaccessible without warning or user action.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities