The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like 'marketking_delete_team_member', 'marketkingrejectuser', 'marketking_save_profile_settings', and many more in all versions up to, and including, 2.0.00. This makes it possible for unauthenticated attackers to delete users, update settings, approve users, and more.
References
Configurations
No configuration.
History
25 Dec 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-25 04:15
Updated : 2024-12-25 04:15
NVD link : CVE-2024-12413
Mitre link : CVE-2024-12413
CVE.ORG link : CVE-2024-12413
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization