Unauthenticated Broken Access Control in MarketKing Plugin by WordPress
CVE-2026-27399
5.3MEDIUM
What is CVE-2026-27399?
The MarketKing plugin for WordPress, specifically versions up to 2.1.40, is susceptible to unauthenticated broken access control. This vulnerability allows unauthorized users to access sensitive operations, potentially leading to compromised user data and site integrity. Proper security practices and timely updates are essential to mitigate this risk.
Affected Version(s)
MarketKing <= 2.1.40