Executive brief
MarketKing is a WooCommerce multivendor marketplace plugin that allows vendors to manage orders and customers. A missing authorization flaw in the refund system allows any authenticated user, even with basic subscriber access, to create fraudulent refund requests against orders they didn't place by exploiting an unprotected AJAX action. This enables attackers to disrupt the marketplace and interfere with other vendors' and customers' orders.
Technical details
The marketking_send_refund AJAX action fails to validate that the authenticated user owns or has permission to refund the specified order, allowing permission escalation. An attacker with subscriber-level access or higher can supply an arbitrary order ID in a crafted AJAX request to create refund requests against any order in the marketplace. The vulnerability requires authentication but allows unauthorized interference with marketplace operations across all orders.
Affected products
- WebWizards MarketKing before 2.1.72
Timeline
- 2026-09-22: disclosed