CVE-2026-93342
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authenticated attackers with subscriber-level access or higher to duplicate any vendor's product by supplying an arbitrary product ID. Attackers can bypass ownership verification to copy any vendor's product listings, including private product metadata, and assign the duplicated copy to their own vendor account without the victim's knowledge or consent.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WebWizards | MarketKing | 0 < 2.1.72 | affected |
Weaknesses
- CWE-862: Missing Authorization
References
- https://marketkingplugin.com/changelog/
- https://wordpress.org/plugins/marketking-multivendor-marketplace-for-woocommerce/
- https://www.vulncheck.com/advisories/marketking-missing-authorization-via-marketking-duplicate-product-ajax
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.