MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher to retrieve the complete vendor directory b
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WebWizards | MarketKing | < 2.1.72 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WebWizards | MarketKing | 0 ~ 2.1.72 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93344 | 6.5 MEDIUM | MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX |
| CVE-2026-93342 | 5.4 MEDIUM | MarketKing < 2.1.72 Missing Authorization via marketking_duplicate_product AJAX |
| CVE-2026-93341 | 4.3 MEDIUM | MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX |
No comments yet