{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/wedevs/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-8761"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Dokan"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["weDevs","WooCommerce"],"content_html":"\u003cp\u003eThe Dokan plugin for WordPress (versions 5.0.1 and earlier) is vulnerable to a severe privilege escalation vulnerability tracked as CVE-2026-8761. The issue originates in the \u003ccode\u003eCustomersController\u003c/code\u003e REST controller located at \u003ccode\u003eincludes/REST/CustomersController.php\u003c/code\u003e. The plugin registers custom REST routes under the \u003ccode\u003e/dokan/v1/customers/\u003c/code\u003e namespace by re-implementing WooCommerce customer CRUD functionality.\u003c/p\u003e\n\u003cp\u003eCritically, the implementation fails to perform an authorization check on the target user object, instead performing a flawed check on the requesting user's role. Consequently, any user with 'Vendor' or 'Seller' capabilities can interact with the API to read, update, or delete any arbitrary user within the WordPress database. An attacker can specifically target an administrator's record and modify the \u003ccode\u003epassword\u003c/code\u003e parameter, resulting in a complete site takeover. This vulnerability poses an extreme risk for multi-vendor WordPress environments utilizing the Dokan plugin.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over the affected WordPress installation. Given the prevalence of Dokan in e-commerce deployments, this vulnerability facilitates unauthorized access to sensitive customer data, order history, and platform settings. If exploited, an attacker can modify administrative account credentials, inject malicious code, or exfiltrate databases associated with the site.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Dokan plugin to a version patched against CVE-2026-8761.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user logs for unexpected modifications to administrative accounts.\u003c/li\u003e\n\u003cli\u003eMonitor REST API traffic for unauthorized \u003ccode\u003ePUT\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e requests targeting the \u003ccode\u003e/wp-json/dokan/v1/customers/\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict access to administrative dashboard functions and API endpoints to trusted IP ranges where feasible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T08:06:36Z","date_published":"2026-08-05T08:06:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-dokan-privilege-escalation/","summary":"An improper authorization flaw in the Dokan plugin for WordPress allows authenticated attackers with vendor-level access to escalate privileges to administrator via manipulation of the REST API.","title":"CVE-2026-8761: Privilege Escalation in Dokan WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-dokan-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - WeDevs","version":"https://jsonfeed.org/version/1.1"}