Executive brief
MarketKing is a WooCommerce multivendor marketplace plugin that allows merchants to build online marketplaces with multiple vendors. A missing authorization flaw in the AJAX product duplication function allows any authenticated user (including low-privilege subscribers) to duplicate and steal any vendor's product listings, including private metadata, and assign them to their own vendor account without permission.
Technical details
The marketking_duplicate_product AJAX action fails to verify that the requesting user owns the product being duplicated, allowing authenticated attackers with subscriber-level or higher roles to copy arbitrary products via direct product ID manipulation. This is a broken access control vulnerability requiring only network access and valid authentication, enabling product theft and intellectual property violations across the marketplace.
Affected products
- WebWizards MarketKing before 2.1.72
Timeline
- 2026-09-22: disclosed