CVE-2026-65494

WordPress Dokan Pro plugin <= 5.0.2 - SQL Injection vulnerability

Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.


We have discovered 686 live websites that are affected by CVE-2026-65494.

Run a Free Instant Scan




Affected Software

Product  Dokan
Category Ecommerce
Vulnerable Domains686 live websites (95% of Dokan install base)
Vulnerable Versions
  • from 0 through 5.0.2
Vulnerable Versions Count93 versions ( 84% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Expatch | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-65494
United States223 websites



Iran83 websites
Germany53 websites
France44 websites
Cyprus41 websites
GB26 websites
India15 websites
Italy15 websites
Spain14 websites
Brazil11 websites

Website Distribution by TLD

Number of websites using CVE-2026-65494
.com380 websites
.fr15 websites
.net15 websites
.com.br12 websites
.de12 websites
.co.uk11 websites
.it10 websites
.nl9 websites
.ch7 websites
.es7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65494

Top websites that are affected by CVE-2026-65494. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States***,***
*******.com Iran***,***
****.**************.com United States***,***
************.com United States***,***
**************.com United States***,***
************.com United States***,***
***.no Norway***,***
********************.**.uk GB*,***,***
******.com United States*,***,***
******************.com United States*,***,***
See full domain list

FAQ

CVE-2026-65494 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Dokan
A total of 686 websites have been identified as vulnerable to CVE-2026-65494, based on global website indexing conducted by WebTechSurvey.
The Dokan is affected by the CVE-2026-65494 vulnerability.
Dokan versions up to and including 5.0.2 are vulnerable to CVE-2026-65494.