Junglewise Threat Intelligence

CVE-2026-93341: MarketKing plugin for WordPress missing authorization in refund AJAX

CVE-2026-93341 · Severity: medium · CVSS 4.3 · Published 2026-09-22

Technologies: WebWizards MarketKing. Vendors: WebWizards.

Executive brief

MarketKing is a WooCommerce multivendor marketplace plugin that allows vendors to manage orders and customers. A missing authorization flaw in the refund system allows any authenticated user, even with basic subscriber access, to create fraudulent refund requests against orders they didn't place by exploiting an unprotected AJAX action. This enables attackers to disrupt the marketplace and interfere with other vendors' and customers' orders.

Technical details

The marketking_send_refund AJAX action fails to validate that the authenticated user owns or has permission to refund the specified order, allowing permission escalation. An attacker with subscriber-level access or higher can supply an arbitrary order ID in a crafted AJAX request to create refund requests against any order in the marketplace. The vulnerability requires authentication but allows unauthorized interference with marketplace operations across all orders.

Affected products

  • WebWizards MarketKing before 2.1.72

Timeline

  • 2026-09-22: disclosed

References

Related threats