T
he Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/85e32913-dc2a-44c9-addd-7abde618e995/ | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/85e32913-dc2a-44c9-addd-7abde618e995/ | Exploit Third Party Advisory |
Configurations
History
24 Feb 2026, 20:58
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:dokan:dokan:*:*:*:*:lite:wordpress:*:* | |
| First Time |
Dokan
Dokan dokan |
21 Nov 2024, 07:19
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://wpscan.com/vulnerability/85e32913-dc2a-44c9-addd-7abde618e995/ - Exploit, Third Party Advisory |
Information
Published : 2024-01-16 16:15
Updated : 2026-02-24 20:58
NVD link : CVE-2022-3194
Mitre link : CVE-2022-3194
CVE.ORG link : CVE-2022-3194
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')