What is CVE-2026-27399?
An unauthenticated broken access control vulnerability exists in MarketKing plugin versions up to 2.1.40. This flaw could allow a remote unauthenticated attacker to gain unauthorized access to restricted resources. Updating to the latest version is recommended.
Azərbaycanca: MarketKing plagininin 2.1.40 və əvvəlki versiyalarında autentifikasiya olmadan qırılmış giriş nəzarəti zəifliyi aşkarlanıb. Bu boşluq uzaqdan autentifikasiya olunmamış hücumçuya məhdudlaşdırılmış resurslara icazəsiz giriş imkanı verə bilər. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the MarketKing plugin are affected by CVE-2026-27399?
MarketKing plugin versions up to 2.1.40 are affected by this vulnerability.
What can an attacker gain by exploiting CVE-2026-27399?
A remote unauthenticated attacker can gain unauthorized access to restricted resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.