Executive brief
MarketKing is a multivendor marketplace plugin for WordPress that manages vendor storefronts, orders, and payouts. A missing authorization flaw in the marketking_get_page_content AJAX handler allows authenticated subscribers to view any vendor's administrative pages—including payout records, financial reports, and dashboards—by manipulating a vendor ID parameter. An attacker could access sensitive financial and operational data belonging to other vendors in the marketplace.
Technical details
The marketking_get_page_content AJAX action fails to properly verify that the requesting user is authorized to access the target vendor's admin pages. An authenticated attacker with subscriber-level or higher privileges can bypass authorization by crafting a request with an arbitrary vendor user ID, gaining access to pages that should be restricted to that vendor's authorized staff. The vulnerability allows horizontal privilege escalation within a multivendor marketplace context.
Affected products
- WebWizards MarketKing before 2.1.72
Timeline
- 2026-09-22: disclosed