HIGH
WebWizards
CVE published 2026-09-22
CVE-2026-93343
The MarketKing plugin for WordPress contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action. This allows authenticated attackers with subscriber-level access or higher to retrieve the complete vendor directory by sending a crafted AJAX request. The vulnerability exposes personally identifiable information of registered vendors, including internal user IDs, usernames [truncated]