Impact
The MarketKing WordPress plugin before version 2.1.72 contains a missing authorization flaw in the marketking_get_page_content AJAX action. Authenticated attackers with at least subscriber privileges can send a vendor ID to retrieve vendor‑specific pages such as payout, financial reports, and dashboard content. This flaw allows the attacker to read confidential vendor information and potentially impersonate vendor administrators, compromising confidentiality and integrity.
Affected Systems
This vulnerability affects all installations of the MarketKing plugin on WordPress that have a version earlier than 2.1.72. The plugin is distributed under WebWizards:MarketKing and is available from the WordPress plugin repository and the vendor site.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity level. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated, so the attack vector is authenticated. Given the ability to view sensitive vendor data, the risk is significant, especially in marketplaces with many vendors.
OpenCVE Enrichment