CVE-2025-5931 Details
Description
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is due to the plugin not properly validating a user's identity prior to updating their password during a staff password reset. This makes it possible for authenticated attackers, with vendor-level access and above, to elevate their privilege to the level of a staff member and then change arbitrary user passwords, including those of administrators in order to gain access to their accounts. By default, the plugin allows customers to become vendors.
A privilege escalation vulnerability has been identified in the Dokan Pro plugin for WordPress, affecting all versions through 4.0.5. The issue arises because the plugin fails to properly verify a user's identity before allowing password changes during staff password resets. This flaw enables authenticated attackers with vendor-level access or higher to escalate their privileges to that of a staff member. Once elevated, they can change passwords for any user, including administrators, to gain unauthorized access to their accounts. By default, the plugin permits customers to become vendors.
Users can update to version 4.0.6 or a newer patched version to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 26, 2025CISA-ADP
Assessed Aug 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dokan Pro | <= 4.0.5 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 26, 2025 | New CVE Received | [email protected] |
Volerion