Missing Authorization in MarketKing Plugin for WordPress
CVE-2026-93344
7.1HIGH
What is CVE-2026-93344?
The MarketKing plugin for WordPress, specifically versions before 2.1.72, is susceptible to a missing authorization vulnerability via the marketking_get_page_content AJAX action. This flaw allows authenticated attackers, with at least subscriber-level access, to bypass authorization measures. They can exploit this vulnerability by providing any vendor user ID in the request, thus gaining unauthorized access to sensitive vendor admin pages such as payout sections and financial reports. This highlights the importance of implementing proper access controls within web applications to safeguard sensitive information.
Affected Version(s)
MarketKing 0 < 2.1.72
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Doniyor Sotiboldiyev (GitHub: @Doniyor2510)
VulnCheck