CVE-2026-93342

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
5.4
MEDIUM

Description

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authenticated attackers with subscriber-level access or higher to duplicate any vendor's product by supplying an arbitrary product ID. Attackers can bypass ownership verification to copy any vendor's product listings, including private product metadata, and assign the duplicated copy to their own vendor account without the victim's knowledge or consent.

Published
September 22, 2026 2:17 PM
Last Modified
September 22, 2026 2:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-862

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.