plugin

Mstore Api Vulnerabilities

71 known security issues reported for the Mstore Api WordPress plugin. Most recent disclosed Aug 11, 2026.

13 critical 3 high 19 medium

Running Mstore Api on your site? Check whether your installed version is affected.

Scan your site free

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.20.0 - Unauthenticated Privilege Escalation

critical

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.20.0. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

CVSS:
9.8
Affected:
up to 4.20.0
Fixed in:
4.21.0
Disclosed:
Aug 11, 2026

CVE-2026-27543 on NVD →

MStore API <= 4.20.0 - Missing Authorization

medium

The MStore API plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.20.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.20.0
Fixed in:
4.21.0
Disclosed:
Aug 3, 2026

CVE-2026-16038 on NVD →

MStore API <= 4.20.0 - Missing Authorization

medium

The MStore API plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.20.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.20.0
Fixed in:
4.21.0
Disclosed:
Aug 3, 2026

CVE-2026-16041 on NVD →

MStore API <= 4.20.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Order and Customer PII Disclosure

medium

The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.20.0. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 4.20.0
Fixed in:
4.21.0
Disclosed:
Aug 3, 2026

CVE-2026-16039 on NVD →

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 - Missing Authorization

medium

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.18.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.18.4
Fixed in:
4.19.0
Disclosed:
Jul 7, 2026

CVE-2026-57375 on NVD →

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 - Missing Authorization

medium

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.18.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.18.4
Fixed in:
4.19.0
Disclosed:
Jun 17, 2026

CVE-2026-54817 on NVD →

MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update

medium

The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist, blocklist, or validation of meta keys. T...

CVSS:
4.3
Affected:
up to 4.18.3
Fixed in:
4.18.4
Disclosed:
Apr 8, 2026

CVE-2026-3568 on NVD →

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation

medium

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level acc...

CVSS:
4.3
Affected:
up to 4.17.5
Fixed in:
4.17.6
Disclosed:
May 26, 2025

CVE-2025-4683 on NVD →

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation

medium

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering. This makes it possible for unauthenticated attackers to to register with the 'wcf...

CVSS:
6.5
Affected:
up to 4.17.4
Fixed in:
4.17.5
Disclosed:
May 1, 2025

CVE-2025-3438 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.16.5

unknown

[en] The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type validation. This makes it possible for authenticated attackers, wi...

Affected:
up to 4.16.5
Fixed in:
4.16.5
Disclosed:
Dec 13, 2024

CVE-2024-12042 on NVD →

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting)

medium

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type validation. This makes it possible for authenticated attackers, with su...

CVSS:
5.4
Affected:
up to 4.16.4
Fixed in:
4.16.5
Disclosed:
Dec 12, 2024

CVE-2024-12042 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.15.8

unknown

[en] The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

Affected:
up to 4.15.8
Fixed in:
4.15.8
Disclosed:
Nov 20, 2024

CVE-2024-11179 on NVD →

MStore API <= 4.15.7 - Authenticated (Subscriber+) SQL Injection

medium

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

CVSS:
6.5
Affected:
up to 4.15.7
Fixed in:
4.15.8
Disclosed:
Nov 19, 2024

CVE-2024-11179 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.15.4

unknown

[en] The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up to, and including, 4.15.3. This makes it possible for authenticated attackers, with subscriber-lev...

Affected:
up to 4.15.4
Fixed in:
4.15.4
Disclosed:
Sep 13, 2024

CVE-2024-8242 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.15.4

unknown

[en] The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function...

Affected:
up to 4.15.4
Fixed in:
4.15.4
Disclosed:
Sep 13, 2024

CVE-2024-8269 on NVD →

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload

medium

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up to, and including, 4.15.3. This makes it possible for authenticated attackers, with subscriber-level ac...

CVSS:
4.3
Affected:
up to 4.15.3
Fixed in:
4.15.4
Disclosed:
Sep 12, 2024

CVE-2024-8242 on NVD →

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration

high

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function. Thi...

CVSS:
7.3
Affected:
up to 4.15.3
Fixed in:
4.15.4
Disclosed:
Sep 12, 2024

CVE-2024-8269 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.15.3

unknown

[en] The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in the 'verify_id_token' function. This makes it possible for unauthenticated attackers to log in as any ex...

Affected:
up to 4.15.3
Fixed in:
4.15.3
Disclosed:
Aug 15, 2024

CVE-2024-7628 on NVD →

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover

high

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in the 'verify_id_token' function. This makes it possible for unauthenticated attackers to log in as any existin...

CVSS:
8.1
Affected:
up to 4.15.2
Fixed in:
4.15.3
Disclosed:
Aug 14, 2024

CVE-2024-7628 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.15.0

unknown

[en] The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and 'firebase_sms_login_v2' functions. This makes it...

Affected:
up to 4.15.0
Fixed in:
4.15.0
Disclosed:
Jul 12, 2024

CVE-2024-6328 on NVD →

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass

critical

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and 'firebase_sms_login_v2' functions. This makes it poss...

CVSS:
9.8
Affected:
up to 4.14.7
Fixed in:
4.15.0
Disclosed:
Jul 11, 2024

CVE-2024-6328 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.10.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in InspireUI MStore API.This issue affects MStore API: from n/a through 4.10.1.

Affected:
up to 4.10.2
Fixed in:
4.10.2
Disclosed:
Dec 29, 2023

CVE-2023-50878 on NVD →

MStore API <= 4.10.1 - Cross-Site Request Forgery

medium

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 4.10.2 (exclusive). This is due to missing or incorrect nonce validation in the templates/admin/mstore-api-admin-dashboard.php file. This makes it possible for unauthenticated attackers to upload an Apple key file via...

CVSS:
4.3
Affected:
up to 4.10.1
Fixed in:
4.10.2
Disclosed:
Dec 26, 2023

CVE-2023-50878 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.0.7

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This issue affects MStore API: from n/a through 4.0.6.

Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Nov 6, 2023

CVE-2023-45055 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.10.8

unknown

[en] The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address. We...

Affected:
up to 4.10.8
Fixed in:
4.10.8
Disclosed:
Nov 3, 2023

CVE-2023-3277 on NVD →

MStore API <= 4.0.6 - Authenticated (Subscriber+) SQL Injection

high

The MStore API plugin for WordPress is vulnerable to SQL Injection via the $name and $search variables in versions up to, and including, 4.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wi...

CVSS:
8.8
Affected:
up to 4.0.6
Fixed in:
4.0.7
Disclosed:
Oct 3, 2023

CVE-2023-45055 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.0.2

unknown

[en] The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenticated attackers to update the firebase server key to push notification when order status changed via a forged reque...

Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
Jul 12, 2023

CVE-2023-3202 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.7

unknown

[en] The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_title function. This makes it possible for unauthenticated attackers to update status order title via a forged request granted they can trick a site administrator into p...

Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Jul 12, 2023

CVE-2023-3199 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.7

unknown

[en] The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Jul 10, 2023

CVE-2023-3209 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.7

unknown

[en] The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Jul 10, 2023

CVE-2023-3131 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.8

unknown

[en] The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocomm...

Affected:
up to 3.9.8
Fixed in:
3.9.8
Disclosed:
Jul 10, 2023

CVE-2023-3077 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.9

unknown

[en] The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.

Affected:
up to 3.9.9
Fixed in:
3.9.9
Disclosed:
Jul 10, 2023

CVE-2023-3076 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.0.2

unknown

[en] The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticat...

Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
Jun 24, 2023

CVE-2023-3197 on NVD →

MStore API <= 4.0.1 - Unauthenticated SQL Injection

critical

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at...

CVSS:
9.8
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
Jun 23, 2023

CVE-2023-3197 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.8

unknown

[en] Unauth. SQL Injection (SQLi) vulnerability in InspireUI MStore API plugin <= 3.9.7 versions.

Affected:
up to 3.9.8
Fixed in:
3.9.8
Disclosed:
Jun 23, 2023

CVE-2022-47614 on NVD →

MStore API <= 3.9.7 - Unauthenticated SQL Injection

critical

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'product_id' parameter in versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenti...

CVSS:
9.8
Affected:
up to 3.9.7
Fixed in:
3.9.8
Disclosed:
Jun 19, 2023

CVE-2023-3077 on NVD →

MStore API <= 3.9.8 - Unauthenticated Privilege Escalation

critical

The MStore API plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.9.8 due to insufficient restriction on roles supplied during registration through the /register REST route. This allows unauthenticated attackers register as administrators.

CVSS:
9.8
Affected:
up to 3.9.8
Fixed in:
3.9.9
Disclosed:
Jun 19, 2023

CVE-2023-3076 on NVD →

MStore API <= 3.9.7 - Unauthenticated SQL Injection

critical

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'store_id' parameter in versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthentica...

CVSS:
9.8
Affected:
up to 3.9.7
Fixed in:
3.9.8
Disclosed:
Jun 19, 2023

CVE-2022-47614 on NVD →

MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation

critical

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address.

CVSS:
9.8
Affected:
up to 4.10.7
Fixed in:
4.10.8
Disclosed:
Jun 19, 2023

CVE-2023-3277 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.7

unknown

[en] The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_message function. This makes it possible for unauthenticated attackers to update new order message via a forged request granted they can trick a site administrator into per...

Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Jun 14, 2023

CVE-2023-3200 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.7

unknown

[en] The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_limit_product function. This makes it possible for unauthenticated attackers to update limit the number of product per category to use cache data in home screen via a forged request...

Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Jun 14, 2023

CVE-2023-3203 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.7

unknown

[en] The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticated attackers to update new order title via a forged request granted they can trick a site administrator into perform...

Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Jun 14, 2023

CVE-2023-3201 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.7

unknown

[en] The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_message function. This makes it possible for unauthenticated attackers to update status order message via a forged request granted they can trick a site administrator in...

Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Jun 14, 2023

CVE-2023-3198 on NVD →

MStore API <= 3.9.6 - Cross-Site Request Forgery to Firebase Server Key Update

medium

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenticated attackers to update the firebase server key to push notification when order status changed via a forged request gr...

CVSS:
4.3
Affected:
up to 3.9.6
Fixed in:
3.9.7
Disclosed:
Jun 13, 2023

CVE-2023-3202 on NVD →

MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Message Update

medium

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_message function. This makes it possible for unauthenticated attackers to update new order message via a forged request granted they can trick a site administrator into performi...

CVSS:
4.3
Affected:
up to 3.9.6
Fixed in:
3.9.7
Disclosed:
Jun 13, 2023

CVE-2023-3200 on NVD →

MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update

medium

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticated attackers to update new order title via a forged request granted they can trick a site administrator into performing a...

CVSS:
4.3
Affected:
up to 3.9.6
Fixed in:
3.9.7
Disclosed:
Jun 13, 2023

CVE-2023-3201 on NVD →

MStore API <= 3.9.6 - Cross-Site Request Forgery to Product Limit Update

medium

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_limit_product function. This makes it possible for unauthenticated attackers to update limit the number of product per category to use cache data in home screen via a forged request grant...

CVSS:
4.3
Affected:
up to 3.9.6
Fixed in:
3.9.7
Disclosed:
Jun 13, 2023

CVE-2023-3203 on NVD →

MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Status Update

medium

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_message function. This makes it possible for unauthenticated attackers to update status order message via a forged request granted they can trick a site administrator into pe...

CVSS:
4.3
Affected:
up to 3.9.6
Fixed in:
3.9.7
Disclosed:
Jun 13, 2023

CVE-2023-3198 on NVD →

MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update

medium

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_title function. This makes it possible for unauthenticated attackers to update status order title via a forged request granted they can trick a site administrator into perfor...

CVSS:
4.3
Affected:
up to 3.9.6
Fixed in:
3.9.7
Disclosed:
Jun 13, 2023

CVE-2023-3199 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.6

unknown

Update the WordPress MStore API plugin to the latest available version (at least 3.9.6). Unknown discovered and reported this Broken Access Control vulnerability in WordPress MStore API Plugin. This vulnerability has been fixed in version 3.9.6.

Affected:
up to 3.9.6
Fixed in:
3.9.6
Disclosed:
Jun 13, 2023

MStore API <= 3.9.6 - Missing Authorization

medium

The MStore API plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions called via AJAX actions such as mstore_delete_json_file, mstore_update_limit_product, mstore_update_firebase_server_key, mstore_update_new_order_title, mstore_update_new_order_mes...

CVSS:
6.5
Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Jun 12, 2023

CVE-2023-3131 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.6

unknown

The MStore API plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions called via AJAX actions such as mstore_delete_json_file, mstore_update_limit_product, mstore_update_firebase_server_key, mstore_update_new_order_title, mstore_update_new_order_mes...

Affected:
up to 3.9.6
Fixed in:
3.9.6
Disclosed:
Jun 12, 2023

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 2.1.6

unknown

[en] The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated attackers to create new administrator accounts, delete existing admin...

Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Jun 7, 2023

CVE-2020-36713 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.3

unknown

[en] The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log i...

Affected:
up to 3.9.3
Fixed in:
3.9.3
Disclosed:
May 25, 2023

CVE-2023-2734 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.3

unknown

[en] The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as...

Affected:
up to 3.9.3
Fixed in:
3.9.3
Disclosed:
May 25, 2023

CVE-2023-2733 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.3

unknown

[en] The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any e...

Affected:
up to 3.9.3
Fixed in:
3.9.3
Disclosed:
May 25, 2023

CVE-2023-2732 on NVD →

MStore API <= 3.9.2 - Authentication Bypass

critical

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existi...

CVSS:
9.8
Affected:
up to 3.9.2
Fixed in:
3.9.3
Disclosed:
May 24, 2023

CVE-2023-2732 on NVD →

MStore API <= 3.9.1 - Authentication Bypass

critical

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as...

CVSS:
9.8
Affected:
up to 3.9.1
Fixed in:
3.9.2
Disclosed:
May 22, 2023

CVE-2023-2734 on NVD →

MStore API <= 3.9.0 - Authentication Bypass

critical

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any...

CVSS:
9.8
Affected:
up to 3.9.0
Fixed in:
3.9.1
Disclosed:
May 17, 2023

CVE-2023-2733 on NVD →

MStore API < 3.4.5 - Arbitrary File Upload

critical

The MStore API plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the api/flutter_woo/config_file REST endpoint in versions before 3.4.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code exec...

CVSS:
9.8
Affected:
up to 3.4.5
Fixed in:
3.4.5
Disclosed:
Oct 5, 2021

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.4.5

unknown

The MStore API plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the api/flutter_woo/config_file REST endpoint in versions before 3.4.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code exec...

Affected:
up to 3.4.5
Fixed in:
3.4.5
Disclosed:
Oct 5, 2021

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.2.0

unknown

[en] A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Mar 18, 2021

CVE-2021-24148 on NVD →

MStore API <= 3.1.9 - Authentication Bypass

critical

A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

CVSS:
9.8
Affected:
up to 3.1.9
Fixed in:
3.2.0
Disclosed:
Feb 2, 2021

CVE-2021-24148 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.2.0

unknown

Bypass vulnerability in Apple login authentication method found by Vincent Datrier in WordPress MStore API plugin (versions <= 3.1.9).

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Feb 2, 2021

MStore API <= 2.1.5 - Authentication Bypass

critical

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated attackers to create new administrator accounts, delete existing administra...

CVSS:
9.8
Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Mar 11, 2020

CVE-2020-36713 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 2.1.6

unknown

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated attackers to create new administrator accounts, delete existing administra...

Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Mar 11, 2020

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 2.1.6

unknown

Unauthenticated Account Create/Edit vulnerability discovered by NinTechNet in WordPress MStore API plugin (versions <= 2.1.5).

Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Mar 11, 2020

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.17.5

unknown
Affected:
up to 4.17.5
Fixed in:
4.17.5

CVE-2025-3438 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 4.17.6

unknown
Affected:
up to 4.17.6
Fixed in:
4.17.6

CVE-2025-4683 on NVD →

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 2.1.6

unknown

The MStore API WordPress plugin was affected by an Unauthenticated Arbitrary Account Creation/Edition security vulnerability.

Affected:
up to 2.1.6
Fixed in:
2.1.6

MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.4.5

unknown

The api/flutter_woo/config_file REST endpoint of the plugin, does not have proper authorisation in place (only checking if the plugin has a license), nor enough validation against the config file sent in the request. As a result, unauthenticated users could use such endpoint to upload a PHP file, leading to RCE We c...

Affected:
up to 3.4.5
Fixed in:
3.4.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database