{"id":"CVE-2020-36748","details":"The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers to trigger an order export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","modified":"2026-08-07T15:14:20.591890Z","published":"2023-07-01T06:15:09.433Z","references":[{"type":"ADVISORY","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/894c875a-078f-4c1f-83d2-4a6e4a309c3e?source=cve"},{"type":"FIX","url":"https://plugins.trac.wordpress.org/changeset/2368433/dokan-lite/trunk/includes/Dashboard/Templates/Orders.php"},{"type":"ARTICLE","url":"https://blog.nintechnet.com/more-wordpress-plugins-and-themes-vulnerable-to-csrf-attacks/"},{"type":"ARTICLE","url":"https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-1/"},{"type":"ARTICLE","url":"https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-2/"},{"type":"ARTICLE","url":"https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-3/"},{"type":"ARTICLE","url":"https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-4/"},{"type":"ARTICLE","url":"https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-5/"},{"type":"EVIDENCE","url":"https://blog.nintechnet.com/25-wordpress-plugins-vulnerable-to-csrf-attacks/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getdokan/dokan","events":[{"introduced":"0"},{"fixed":"e672627e7fb322cb54f183b46161ca5fec959289"}],"database_specific":{"cpe":"cpe:2.3:a:dokan:dokan:*:*:*:*:lite:wordpress:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.0.9"}],"source":"CPE_RANGE"}}],"versions":["v2.5.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36748.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}