Junglewise Threat Intelligence

CVE-2026-27399: WebWizards MarketKing broken access control

CVE-2026-27399 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Technologies: WebWizards / Kings Plugins MarketKing. Vendors: WebWizards.

Executive brief

MarketKing is a multi-vendor marketplace plugin for WordPress that allows site owners to run stores with multiple independent sellers. A security flaw in versions 2.1.40 and earlier allows unauthenticated users to perform actions they should not have permission for due to missing authorization checks. While the impact is rated as medium, it could allow unauthorized changes to certain site settings or data without requiring a login.

Technical details

The MarketKing plugin for WordPress (versions <= 2.1.40) is vulnerable to broken access control due to missing authorization (CWE-862) on certain functions. An unauthenticated remote attacker can exploit this vulnerability by sending crafted requests to the affected site, potentially allowing them to execute actions that should be restricted to higher-privileged users. The vulnerability stems from a lack of proper authentication or nonce token checks. The issue is resolved in version 2.1.50.

Affected products

  • WebWizards / Kings Plugins MarketKing <= 2.1.40

Timeline

  • 2025-11-10: disclosed: Reported by Legion Hunter to Patchstack
  • 2026-07-21: advisory: Patchstack advisory published
  • 2026-07-23: patched: NVD publication and patch availability confirmed in version 2.1.50

References

Related threats