CVE-2026-93343: Missing Authorization in WebWizards MarketKing
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher to retrieve the complete vendor directory by sending a crafted AJAX request. Attackers can exploit the absence of capability checks in the vendor management action to retrieve internal user IDs, usernames, and email addresses of all registered vendors, exposing personally identifiable information to any logged-in user regardless of role.
AI Analysis
Technical Summary
CVE-2026-93343 describes a missing authorization vulnerability in the MarketKing WordPress plugin prior to version 2.1.72. Specifically, the marketking_admin_vendors_ajax AJAX action does not enforce capability checks, enabling authenticated users with minimal privileges (subscriber-level or higher) to send crafted AJAX requests that retrieve the complete vendor directory. This results in exposure of internal user IDs, usernames, and email addresses of all registered vendors, violating access control and confidentiality principles.
Potential Impact
The vulnerability allows any logged-in user, regardless of role, to access sensitive personally identifiable information (PII) of all vendors registered in the MarketKing plugin. This unauthorized data disclosure can lead to privacy violations and potential targeted attacks against vendors. There is no indication of privilege escalation or remote code execution, but the confidentiality breach is significant.
Mitigation Recommendations
A fix is available in MarketKing version 2.1.72 that addresses this missing authorization vulnerability. Users should upgrade to version 2.1.72 or later to remediate this issue. Since the vendor advisory or patch links are not provided, verify the availability of the update from the official WebWizards source before applying.
CVE-2026-93343: Missing Authorization in WebWizards MarketKing
Description
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher to retrieve the complete vendor directory by sending a crafted AJAX request. Attackers can exploit the absence of capability checks in the vendor management action to retrieve internal user IDs, usernames, and email addresses of all registered vendors, exposing personally identifiable information to any logged-in user regardless of role.
CVSS v4.0
Score 7.1high
Affected software
WebWizards
MarketKing
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93343 describes a missing authorization vulnerability in the MarketKing WordPress plugin prior to version 2.1.72. Specifically, the marketking_admin_vendors_ajax AJAX action does not enforce capability checks, enabling authenticated users with minimal privileges (subscriber-level or higher) to send crafted AJAX requests that retrieve the complete vendor directory. This results in exposure of internal user IDs, usernames, and email addresses of all registered vendors, violating access control and confidentiality principles.
Potential Impact
The vulnerability allows any logged-in user, regardless of role, to access sensitive personally identifiable information (PII) of all vendors registered in the MarketKing plugin. This unauthorized data disclosure can lead to privacy violations and potential targeted attacks against vendors. There is no indication of privilege escalation or remote code execution, but the confidentiality breach is significant.
Mitigation Recommendations
A fix is available in MarketKing version 2.1.72 that addresses this missing authorization vulnerability. Users should upgrade to version 2.1.72 or later to remediate this issue. Since the vendor advisory or patch links are not provided, verify the availability of the update from the official WebWizards source before applying.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-17T18:41:40.757Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab28aa7f7a7c5410641fa58
Added to database: 09/22/2026, 14:03:19 UTC
Last enriched: 09/22/2026, 14:17:47 UTC
Last updated: 09/23/2026, 01:58:07 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.