PT-2026-96733 · WordPress · Marketking
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MarketKing plugin for WordPress versions prior to 2.1.72
Description
An authorization flaw exists in the
marketking duplicate product AJAX action. Authenticated users with subscriber-level access or higher can duplicate any vendor's product by providing an arbitrary product ID. This allows attackers to bypass ownership verification to copy product listings and private product metadata, assigning the duplicated content to their own vendor account without consent.Recommendations
Update MarketKing plugin for WordPress to version 2.1.72 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marketking