Description
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary vendor administrator panel pages by supplying an arbitrary vendor user ID. Attackers can bypass authorization controls by submitting a target vendor ID in the request to access payout pages, financial reports, and vendor dashboard content belonging to any vendor in the marketplace.
Published: 2026-09-22
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Missing Authorization Enables Unauthorized Vendor Page Access
Action: Patch
AI Analysis

Impact

The MarketKing WordPress plugin before version 2.1.72 contains a missing authorization flaw in the marketking_get_page_content AJAX action. Authenticated attackers with at least subscriber privileges can send a vendor ID to retrieve vendor‑specific pages such as payout, financial reports, and dashboard content. This flaw allows the attacker to read confidential vendor information and potentially impersonate vendor administrators, compromising confidentiality and integrity.

Affected Systems

This vulnerability affects all installations of the MarketKing plugin on WordPress that have a version earlier than 2.1.72. The plugin is distributed under WebWizards:MarketKing and is available from the WordPress plugin repository and the vendor site.

Risk and Exploitability

The CVSS score is 7.1, indicating a high severity level. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated, so the attack vector is authenticated. Given the ability to view sensitive vendor data, the risk is significant, especially in marketplaces with many vendors.

Generated by OpenCVE AI on September 22, 2026 at 15:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to MarketKing 2.1.72 or later
  • Restrict subscriber and non‑admin roles from accessing the marketking_get_page_content AJAX action
  • Conduct an audit of role capabilities and remove any permissions that expose vendor panel data

Generated by OpenCVE AI on September 22, 2026 at 15:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Webwizards
Webwizards marketking
Wordpress
Wordpress wordpress
Vendors & Products Webwizards
Webwizards marketking
Wordpress
Wordpress wordpress

Tue, 22 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary vendor administrator panel pages by supplying an arbitrary vendor user ID. Attackers can bypass authorization controls by submitting a target vendor ID in the request to access payout pages, financial reports, and vendor dashboard content belonging to any vendor in the marketplace.
Title MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Webwizards Marketking
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T14:33:13.076Z

Reserved: 2026-09-17T18:41:40.757Z

Link: CVE-2026-93344

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T15:17:21.690

Modified: 2026-09-22T15:17:21.690

Link: CVE-2026-93344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T15:45:17Z

Weaknesses