Mstoreapp Mobile <= 2.08 & <= 9.0.1 - Unauthenticated Privilege Escalation
criticalMultiple plugins and/or themes for WordPress are vulnerable to Privilege Escalation in various versions. This is due to 'mstoreapp-google_connect' AJAX endpoint not properly verifying a user's identify prior to authenticating them. This makes it possible for unauthenticated attackers to to gain access to other user's a...
- CVSS:
- 9.8
- Affected:
- up to 9.0.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 31, 2025