A vulnerability classified as critical has been found in DokanInc Dokan Plugin up to 5.0.1 on WordPress. This impacts an unknown function of the file includes/REST/CustomersController.php of the component CustomersController. The manipulation of the argument Password leads to improper privilege management.

This vulnerability is documented as CVE-2026-8761. The attack can be initiated remotely. There is not any exploit available.