CVE-2026-93344: MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketkinggetpagecontent AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary vendor administrator panel pages by supplying an arbitrary vendor user ID. Attackers can bypass authorization controls by submitting a target vendor ID in the request to access payout pages, financial reports, and vendor dashboard content belonging to any vendor in the marketplace.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with subscriber-level access or higher can exploit it. The attacker does not need vendor administrator privileges for the target vendor.
What information does an attacker need to access another vendor's data?
The attacker needs to submit the user ID of a target vendor in a request to the marketking_get_page_content AJAX action. This can expose that vendor's administrator-panel content, including payout pages, financial reports, and dashboard content.
Which installations are affected?
MarketKing versions before 2.1.72 are affected. The available information does not state whether any particular configuration or marketplace setup prevents exploitation.
How can I determine whether exploitation may have occurred?
Review requests to the marketking_get_page_content AJAX action for vendor user IDs that do not belong to the authenticated requester. Also investigate unexpected access to vendor payout pages, financial reports, or dashboard content by subscriber-level accounts.