Description
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticated attackers with subscriber-level access or higher to create refund requests against any order by supplying an arbitrary order ID. Attackers can submit crafted AJAX requests targeting any order ID to create fraudulent refund requests against orders they did not place, enabling marketplace disruption and unauthorized interference with other users' orders.
Published: 2026-09-22
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Refund Creation
Action: Patch Immediately
AI Analysis

Impact

MarketKing plugin for WordPress contains a missing authorization check in the marketking_send_refund AJAX action that allows any authenticated user with at least subscriber-level access to create refund requests for any order by specifying an arbitrary order ID. This flaw enables attackers to fabricate refund requests against orders they did not place. The description does not explicitly state financial impact, but unauthorized refunds could potentially lead to loss of revenue or customer trust, inferred from the fact that refunds are processed automatically.

Affected Systems

The vulnerability affects the WebWizards MarketKing plugin for WordPress versions prior to 2.1.72. All sites running an earlier version of this plugin are susceptible until they are updated.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS is not available, so there is no published estimate of recent exploitation activity, and the issue is not currently listed in the CISA KEV catalog. The attack requires only authenticated access at the subscriber level – a role that is typically granted to vendors or sellers – and can be executed remotely via crafted AJAX requests. Although the effect is limited to creating refund requests, the potential for financial harm and operational disruption makes the risk significant for any marketplace operator.

Generated by OpenCVE AI on September 22, 2026 at 15:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MarketKing plugin to version 2.1.72 or later.
  • Review and tighten user roles so that only users who truly need refund capabilities retain subscriber‑level or higher access.
  • Continuously monitor order and refund logs for unexpected or unauthorized refund requests after applying the update.

Generated by OpenCVE AI on September 22, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Webwizards
Webwizards marketking
Wordpress
Wordpress wordpress
Vendors & Products Webwizards
Webwizards marketking
Wordpress
Wordpress wordpress

Tue, 22 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticated attackers with subscriber-level access or higher to create refund requests against any order by supplying an arbitrary order ID. Attackers can submit crafted AJAX requests targeting any order ID to create fraudulent refund requests against orders they did not place, enabling marketplace disruption and unauthorized interference with other users' orders.
Title MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Webwizards Marketking
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T14:05:30.163Z

Reserved: 2026-09-17T18:41:40.757Z

Link: CVE-2026-93341

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T14:17:18.070

Modified: 2026-09-22T15:17:21.560

Link: CVE-2026-93341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T16:30:11Z

Weaknesses