Missing Authorization Vulnerability in MarketKing Plugin for WordPress
CVE-2026-93342
5.3MEDIUM
What is CVE-2026-93342?
The MarketKing plugin for WordPress prior to version 2.1.72 is susceptible to a missing authorization vulnerability. This flaw exists within the marketking_duplicate_product AJAX action, enabling authenticated attackers with subscriber-level access or higher to duplicate any vendor's products by merely providing an arbitrary product ID. Consequently, attackers can circumvent ownership verification processes, allowing them to replicate any vendor's product listings—along with private product metadata—and assign these duplicates to their own vendor accounts without the acknowledgment or consent of the original vendor.
Affected Version(s)
MarketKing 0 < 2.1.72
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Doniyor Sotiboldiyev (GitHub: @Doniyor2510)
VulnCheck