The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like 'marketking_delete_team_member', 'marketkingrejectuser', 'marketking_save_profile_settings', and many more in all versions up to, and including, 2.0.00. This makes it possible for unauthenticated attackers to delete users, update settings, approve users, and more.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 25 Dec 2024 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like 'marketking_delete_team_member', 'marketkingrejectuser', 'marketking_save_profile_settings', and many more in all versions up to, and including, 2.0.00. This makes it possible for unauthenticated attackers to delete users, update settings, approve users, and more. | |
Title | MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution <= 2.0.00 - Missing Authorization | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-25T03:21:31.601Z
Updated: 2024-12-27T15:17:35.716Z
Reserved: 2024-12-10T15:41:24.508Z
Link: CVE-2024-12413
Vulnrichment
Updated: 2024-12-27T15:17:31.981Z
NVD
Status : Received
Published: 2024-12-25T04:15:06.607
Modified: 2024-12-25T04:15:06.607
Link: CVE-2024-12413
Redhat
No data.