Impact
Unauthenticated broken access control in the WordPress MarketKing plugin allows attackers to invoke privileged operations without valid credentials. The flaw is a CWE‑862 weakness in access control enforcement. The impact is unauthorized access to marketplace management functions, but the exact extent of damage depends on the plugin’s implementation and the site configuration.
Affected Systems
The affected product is the WordPress MarketKing plugin for the WebWizards vendor, specifically any installation using version 2.1.40 or lower. Sites that rely on this plugin for multi‑vendor marketplace functionality are therefore exposed to the broken access control flaw.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the medium‑severity range. The EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the network to the WordPress site, as it requires no authentication and can be performed by sending crafted HTTP requests to the plugin’s endpoints.
OpenCVE Enrichment