CVE-2026-93344: MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX

Published Sep 22, 2026
·
Updated

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketkinggetpagecontent AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary vendor administrator panel pages by supplying an arbitrary vendor user ID. Attackers can bypass authorization controls by submitting a target vendor ID in the request to access payout pages, financial reports, and vendor dashboard content belonging to any vendor in the marketplace.

Affected Software

1 affected component
MarketKing MarketKing<2.1.72

Event History

Sep 22, 2026
CVE Published
via MITRE·02:01 PM
Data Sourced
via MITRE·02:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated WordPress user with subscriber-level access or higher can exploit it. The attacker does not need vendor administrator privileges for the target vendor.

2

What information does an attacker need to access another vendor's data?

The attacker needs to submit the user ID of a target vendor in a request to the marketking_get_page_content AJAX action. This can expose that vendor's administrator-panel content, including payout pages, financial reports, and dashboard content.

3

Which installations are affected?

MarketKing versions before 2.1.72 are affected. The available information does not state whether any particular configuration or marketplace setup prevents exploitation.

4

How can I determine whether exploitation may have occurred?

Review requests to the marketking_get_page_content AJAX action for vendor user IDs that do not belong to the authenticated requester. Also investigate unexpected access to vendor payout pages, financial reports, or dashboard content by subscriber-level accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203