Junglewise Threat Intelligence

CVE-2026-93344: MarketKing plugin for WordPress missing authorization in AJAX action

CVE-2026-93344 · Severity: medium · CVSS 6.5 · Published 2026-09-22

Technologies: WebWizards MarketKing. Vendors: WebWizards.

Executive brief

MarketKing is a multivendor marketplace plugin for WordPress that manages vendor storefronts, orders, and payouts. A missing authorization flaw in the marketking_get_page_content AJAX handler allows authenticated subscribers to view any vendor's administrative pages—including payout records, financial reports, and dashboards—by manipulating a vendor ID parameter. An attacker could access sensitive financial and operational data belonging to other vendors in the marketplace.

Technical details

The marketking_get_page_content AJAX action fails to properly verify that the requesting user is authorized to access the target vendor's admin pages. An authenticated attacker with subscriber-level or higher privileges can bypass authorization by crafting a request with an arbitrary vendor user ID, gaining access to pages that should be restricted to that vendor's authorized staff. The vulnerability allows horizontal privilege escalation within a multivendor marketplace context.

Affected products

  • WebWizards MarketKing before 2.1.72

Timeline

  • 2026-09-22: disclosed

References

Related threats