Missing Authorization in MarketKing Plugin for WordPress
CVE-2026-93341
5.3MEDIUM
What is CVE-2026-93341?
The MarketKing plugin for WordPress suffers from a missing authorization vulnerability in the 'marketking_send_refund' AJAX action. This issue enables authenticated attackers with subscriber-level access or higher to forge refund requests against any order simply by providing an arbitrary order ID. By exploiting this vulnerability, malicious actors can submit specially crafted AJAX requests to create unauthorized refund requests for orders they did not place. This can result in significant disruption within the marketplace and unauthorized access to user transactions.
Affected Version(s)
MarketKing 0 < 2.1.72
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Doniyor Sotiboldiyev (GitHub: @Doniyor2510)
VulnCheck