PT-2026-96732 · WordPress · Marketking
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MarketKing plugin for WordPress versions prior to 2.1.72
Description
An authorization flaw exists in the
marketking send refund AJAX action. Authenticated users with subscriber-level access or higher can create fraudulent refund requests for any order by providing an arbitrary order ID. This is achieved by submitting crafted AJAX requests, allowing unauthorized interference with orders not placed by the attacker and causing marketplace disruption.Recommendations
Update the MarketKing plugin for WordPress to version 2.1.72 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marketking