Impact
The vulnerability in the MarketKing plugin allows unauthenticated users to bypass normal access controls. An attacker could potentially execute privileged operations such as modifying marketplace settings, viewing or manipulating vendor data, or performing other actions normally restricted to authenticated administrators, thereby compromising the confidentiality, integrity, and availability of the e‑commerce platform.
Affected Systems
This issue affects installations of the WebWizards MarketKing WordPress plugin with versions 2.1.70 and earlier. The vulnerability is present in all releases up to and including 2.1.70; versions 2.1.71 and 2.1.72 are not affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not currently documented. However, the attack vector is inferred to be remote via the web interface, requiring no authentication, which could allow an attacker with network access to the WordPress site to exploit the flaw.
OpenCVE Enrichment