CVE-2026-93344: Missing Authorization in WebWizards MarketKing
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary vendor administrator panel pages by supplying an arbitrary vendor user ID. Attackers can bypass authorization controls by submitting a target vendor ID in the request to access payout pages, financial reports, and vendor dashboard content belonging to any vendor in the marketplace.
AI Analysis
Technical Summary
CVE-2026-93344 describes a missing authorization vulnerability in the MarketKing WordPress plugin prior to version 2.1.72. The vulnerability exists in the marketking_get_page_content AJAX action, which fails to properly verify the authorization of authenticated users with subscriber-level privileges or higher. By submitting an arbitrary vendor user ID, an attacker can bypass authorization controls and access sensitive administrative pages belonging to any vendor in the marketplace, including payout and financial data.
Potential Impact
An attacker with subscriber-level or higher access can view sensitive vendor administrative information such as payout pages, financial reports, and dashboard content for any vendor in the marketplace. This unauthorized access could lead to information disclosure and potential misuse of vendor financial data.
Mitigation Recommendations
A fix is available in MarketKing version 2.1.72. Users should update to version 2.1.72 or later to remediate this missing authorization vulnerability.
CVE-2026-93344: Missing Authorization in WebWizards MarketKing
Description
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary vendor administrator panel pages by supplying an arbitrary vendor user ID. Attackers can bypass authorization controls by submitting a target vendor ID in the request to access payout pages, financial reports, and vendor dashboard content belonging to any vendor in the marketplace.
CVSS v4.0
Score 7.1high
Affected software
WebWizards
MarketKing
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93344 describes a missing authorization vulnerability in the MarketKing WordPress plugin prior to version 2.1.72. The vulnerability exists in the marketking_get_page_content AJAX action, which fails to properly verify the authorization of authenticated users with subscriber-level privileges or higher. By submitting an arbitrary vendor user ID, an attacker can bypass authorization controls and access sensitive administrative pages belonging to any vendor in the marketplace, including payout and financial data.
Potential Impact
An attacker with subscriber-level or higher access can view sensitive vendor administrative information such as payout pages, financial reports, and dashboard content for any vendor in the marketplace. This unauthorized access could lead to information disclosure and potential misuse of vendor financial data.
Mitigation Recommendations
A fix is available in MarketKing version 2.1.72. Users should update to version 2.1.72 or later to remediate this missing authorization vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-17T18:41:40.757Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab291c2f7a7c541064a6ac1
Added to database: 09/22/2026, 14:33:38 UTC
Last enriched: 09/22/2026, 14:47:40 UTC
Last updated: 09/22/2026, 14:48:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.