Medium 5.3
2026-05-02< 4.3.2
CVE-2026-3504
Minimum safe version
4.3.2
Update to 4.3.2 or later to address 14 fixable vulnerabilities
CVE-2026-3504
CVE-2026-24359
CVE-2025-14977
CVE-2025-53425
CVE-2020-36748
CVE-2023-34382
Dokan <=3.7.19 - Authenticated(Shop Manager+) PHP Object Injection via create_dummy_vendor
CVE-2021-4342
CVE-2023-26525
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
CVE-2022-3194
CVE-2022-3915
WordPress Dokan plugin <= 3.0.8 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Dokan plugin <= 3.2.0 - Cross-Site Request Forgery (CSRF) vulnerability