CVE-2026-85311: WordPress MarketKing plugin <= 2.1.60 - Broken Access Control vulnerability
Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects MarketKing: from n/a through 2.1.60.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MarketKing pluginto a version that resolves this vulnerability.Fixed in 2.1.70
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates that it can be exploited over the network without privileges or user interaction. The provided information does not identify any additional conditions or affected user roles.
Which MarketKing versions are affected?
MarketKing versions through 2.1.60 are affected. The earliest affected version is not specified.
What is the potential impact?
The available severity data indicates an integrity impact, with no reported confidentiality or availability impact. The issue is categorized as broken access control caused by missing authorization.