The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.
History

Tue, 24 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dokan
Dokan dokan
CPEs cpe:2.3:a:wedevs:dokan:*:*:*:*:*:wordpress:*:* cpe:2.3:a:dokan:dokan:*:*:*:*:lite:wordpress:*:*
Vendors & Products Wedevs
Wedevs dokan
Dokan
Dokan dokan

Mon, 02 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:53:36.500Z

Updated: 2025-06-02T15:10:22.999Z

Reserved: 2022-09-13T10:02:00.257Z

Link: CVE-2022-3194

cve-icon Vulnrichment

Updated: 2024-08-03T01:00:10.810Z

cve-icon NVD

Status : Analyzed

Published: 2024-01-16T16:15:09.883

Modified: 2026-02-24T20:58:39.753

Link: CVE-2022-3194

cve-icon Redhat

No data.