Impact
The WordPress MarketKing plugin from Kings Plugins contains a Missing Authorization vulnerability that allows an attacker to bypass access controls and perform restricted actions on the site. This flaw is based on CWE‑862, Broken Access Control. The primary impact is unauthorized access to plugin functionality, which could lead to data manipulation or exposure.
Affected Systems
All WordPress sites using MarketKing version 2.1.60 or earlier, including any that have never upgraded beyond the initial release, are affected. The vulnerability applies to every installation of this plugin without a version upgrade.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, but the EPSS score is not available, providing no insight into current exploit probability. The flaw is not listed in the CISA KEV catalog. Attackers can likely exploit the issue via the web interface if they can reach the plugin’s endpoints, and no public exploit is documented.
OpenCVE Enrichment