PT-2026-96734 · WordPress · Marketking
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MarketKing plugin for WordPress versions prior to 2.1.72
Description
An authorization flaw exists in the
marketking admin vendors ajax AJAX action. Authenticated users with subscriber-level access or higher can send a crafted AJAX request to bypass capability checks in the vendor management action. This allows the retrieval of the complete vendor directory, exposing personally identifiable information such as internal user IDs, usernames, and email addresses of all registered vendors.Recommendations
Update MarketKing plugin for WordPress to version 2.1.72 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marketking