Executive brief
MarketKing is a popular WordPress plugin that enables multi-vendor marketplace functionality for WooCommerce-powered stores. A broken access control vulnerability allows authenticated users to view pages or perform actions they should not have permission to access, such as viewing other users' sensitive data or administrative functions. This could lead to unauthorized access to private customer information, orders, or marketplace settings.
Technical details
MarketKing versions up to 2.1.60 contain a broken access control vulnerability (CWE-284) where insufficient permission checks allow users to access resources or perform actions beyond their intended privilege level. The vulnerability is network-reachable and can be exploited by an authenticated user or low-privilege account holder (such as a customer or vendor) without requiring additional user interaction. An attacker can access pages and data meant for administrators or other users with higher privileges. The vulnerability has been patched in version 2.1.70 and later.
Affected products
- Kings Plugins MarketKing up to 2.1.60
Timeline
- 2026-08-23: disclosed: Reported by sungbyeongchan
- 2026-09-04: advisory: Published by Patchstack
- 2026-09-04: patched: Version 2.1.70 available