Missing Authorization in MarketKing Plugin for WordPress
CVE-2026-93341

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2026

What is CVE-2026-93341?

The MarketKing plugin for WordPress suffers from a missing authorization vulnerability in the 'marketking_send_refund' AJAX action. This issue enables authenticated attackers with subscriber-level access or higher to forge refund requests against any order simply by providing an arbitrary order ID. By exploiting this vulnerability, malicious actors can submit specially crafted AJAX requests to create unauthorized refund requests for orders they did not place. This can result in significant disruption within the marketplace and unauthorized access to user transactions.

Affected Version(s)

MarketKing 0 < 2.1.72

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Doniyor Sotiboldiyev (GitHub: @Doniyor2510)
VulnCheck
.