The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Managers to install and activate arbitrary Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 from WordPress.org.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-16576 exploits improper privilege validation in the Dokan WordPress plugin's admin REST API routes. The vulnerability allows users with lower-privilege roles—such as Shop Managers—to install and activate arbitrary plugins by bypassing capability checks that should restrict these actions to administrative users only. This represents a classic privilege escalation flaw (CWE-284: Improper Access Control) affecting WooCommerce multivendor marketplaces. Any WordPress site running Dokan before version 5.0.14 is at risk, with particular exposure for installations granting Shop Manager roles to third-party vendors or marketplace participants who could leverage this to inject malicious code into the platform.
While this CVE lacks mapped MITRE ATT&CK techniques, Casky.ai's 754 security skills enable practitioners to identify the behavioral patterns underlying this vulnerability through Claude AI's extended reasoning. A practitioner would recognize this as Privilege Escalation (T1134) combined with Exploitation of Software vulnerabilities (T1203). Casky's skills would flag suspicious REST API activity showing lower-privileged users accessing plugin installation endpoints, detect unauthorized capability delegation, and identify anomalous plugin activation patterns. By analyzing API request logs and user action logs through Casky's security skills framework, practitioners can spot users without install_plugins capabilities successfully triggering plugin installation—a clear indicator of this capability-check bypass being exploited.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-16576. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation