CVE-2026-94080: WordPress MarketKing plugin <= 2.1.70 - Broken Access Control vulnerability
Published Sep 23, 2026
·Updated
Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
Affected Software
1 affected component
WordPress MarketKing<=2.1.70
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MarketKing Pluginto a version that resolves this vulnerability.Fixed in 2.1.72
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation over the network.
2
Which installations are affected?
MarketKing plugin versions 2.1.70 and earlier are identified as affected. The provided information does not state whether any particular WordPress or WooCommerce configuration changes exposure.
3
What is the potential impact?
The supplied severity vector indicates an integrity impact only, with no stated confidentiality or availability impact. The vulnerability is rated medium severity with a CVSS score of 5.3.