PatchSiren

WebWizards CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WebWizards CVE published 2026-09-22

CVE-2026-93343

The MarketKing plugin for WordPress contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action. This allows authenticated attackers with subscriber-level access or higher to retrieve the complete vendor directory by sending a crafted AJAX request. The vulnerability exposes personally identifiable information of registered vendors, including internal user IDs, usernames [truncated]