PT-2026-96734 · WordPress · Marketking

·

CVE-2026-93343

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MarketKing plugin for WordPress versions prior to 2.1.72
Description An authorization flaw exists in the marketking admin vendors ajax AJAX action. Authenticated users with subscriber-level access or higher can send a crafted AJAX request to bypass capability checks in the vendor management action. This allows the retrieval of the complete vendor directory, exposing personally identifiable information such as internal user IDs, usernames, and email addresses of all registered vendors.
Recommendations Update MarketKing plugin for WordPress to version 2.1.72 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93343

Affected Products

Marketking