Junglewise Threat Intelligence

CVE-2026-93342: MarketKing plugin for WordPress missing authorization in AJAX action

CVE-2026-93342 · Severity: medium · CVSS 5.4 · Published 2026-09-22

Technologies: WebWizards MarketKing. Vendors: WebWizards.

Executive brief

MarketKing is a WooCommerce multivendor marketplace plugin that allows merchants to build online marketplaces with multiple vendors. A missing authorization flaw in the AJAX product duplication function allows any authenticated user (including low-privilege subscribers) to duplicate and steal any vendor's product listings, including private metadata, and assign them to their own vendor account without permission.

Technical details

The marketking_duplicate_product AJAX action fails to verify that the requesting user owns the product being duplicated, allowing authenticated attackers with subscriber-level or higher roles to copy arbitrary products via direct product ID manipulation. This is a broken access control vulnerability requiring only network access and valid authentication, enabling product theft and intellectual property violations across the marketplace.

Affected products

  • WebWizards MarketKing before 2.1.72

Timeline

  • 2026-09-22: disclosed

References

Related threats