Missing Authorization in MarketKing Plugin for WordPress
CVE-2026-93344

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2026

What is CVE-2026-93344?

The MarketKing plugin for WordPress, specifically versions before 2.1.72, is susceptible to a missing authorization vulnerability via the marketking_get_page_content AJAX action. This flaw allows authenticated attackers, with at least subscriber-level access, to bypass authorization measures. They can exploit this vulnerability by providing any vendor user ID in the request, thus gaining unauthorized access to sensitive vendor admin pages such as payout sections and financial reports. This highlights the importance of implementing proper access controls within web applications to safeguard sensitive information.

Affected Version(s)

MarketKing 0 < 2.1.72

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Doniyor Sotiboldiyev (GitHub: @Doniyor2510)
VulnCheck
.