Loading vulnerability details…
CVSS v3.1
5.4
EPSS
0.49%
Published
Jan 16, 2024
Modified
Feb 24, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NWeaknesses (CWE)
Affected Products (1)
References (2)