WordPress · Marketking · CVE-2026-93343
**Name of the Vulnerable Software and Affected Versions**
MarketKing plugin for WordPress versions prior to 2.1.72
**Description**
An authorization flaw exists in the `marketking admin vendors ajax` AJAX action. Authenticated users with subscriber-level access or higher can send a crafted AJAX request to bypass capability checks in the vendor management action. This allows the retrieval of the complete vendor directory, exposing personally identifiable information such as internal user IDs, usernames, and email addresses of all registered vendors.
**Recommendations**
Update MarketKing plugin for WordPress to version 2.1.72 or later.