Impact
MarketKing plugin for WordPress contains a missing authorization check in the marketking_send_refund AJAX action that allows any authenticated user with at least subscriber-level access to create refund requests for any order by specifying an arbitrary order ID. This flaw enables attackers to fabricate refund requests against orders they did not place. The description does not explicitly state financial impact, but unauthorized refunds could potentially lead to loss of revenue or customer trust, inferred from the fact that refunds are processed automatically.
Affected Systems
The vulnerability affects the WebWizards MarketKing plugin for WordPress versions prior to 2.1.72. All sites running an earlier version of this plugin are susceptible until they are updated.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available, so there is no published estimate of recent exploitation activity, and the issue is not currently listed in the CISA KEV catalog. The attack requires only authenticated access at the subscriber level – a role that is typically granted to vendors or sellers – and can be executed remotely via crafted AJAX requests. Although the effect is limited to creating refund requests, the potential for financial harm and operational disruption makes the risk significant for any marketplace operator.
OpenCVE Enrichment