CVE-2024-12413: MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution <= 2.0.00 - Missing Authorization
The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like 'marketkingdeleteteammember', 'marketkingrejectuser', 'marketkingsaveprofilesettings', and many more in all versions up to, and including, 2.0.00. This makes it possible for unauthenticated attackers to delete users, update settings, approve users, and more.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12413?
CVE-2024-12413 has been classified as a critical vulnerability due to unauthorized access risk.
How do I fix CVE-2024-12413?
To remediate CVE-2024-12413, update the MarketKing plugin to version 2.0.01 or later.
What are the potential impacts of CVE-2024-12413?
CVE-2024-12413 could allow unauthorized users to delete team members and modify profile settings.
Which versions are affected by CVE-2024-12413?
CVE-2024-12413 affects all versions of the MarketKing plugin up to and including 2.0.00.
Who is the vendor of the software affected by CVE-2024-12413?
The vendor of the software affected by CVE-2024-12413 is MarketKing.