MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary vendor administrator pane
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WebWizards | MarketKing | < 2.1.72 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WebWizards | MarketKing | 0 ~ 2.1.72 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93343 | 6.5 MEDIUM | MarketKing < 2.1.72 Missing Authorization via marketking_admin_vendors_ajax |
| CVE-2026-93342 | 5.4 MEDIUM | MarketKing < 2.1.72 Missing Authorization via marketking_duplicate_product AJAX |
| CVE-2026-93341 | 4.3 MEDIUM | MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX |
No comments yet