HomeWordPress vulnerabilitiesMStore API
MStore API vulnerabilities
MStore API has 35 known vulnerabilities in this database. The most recent published record is dated 2 Oct 2026.
- Known vulnerabilities
- 35
- Active installs
- 2,000+
- Latest version
- 4.22.1
- Last updated
- 29 Sep 2026
- Most recent
- 2 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Broken access control CVE-2026-97219 | Medium 4.3 | Before 4.22.1 | Fixed in 4.22.1 | 5 d ago |
| Authentication bypass CVE-2026-13447 | Critical 9.8 | Up to 4.20.0 | Fixed in a later version (latest 4.22.1) | 5 Sep 2026 |
| Broken access control CVE-2026-18234 | Medium 6.5 | Before 4.21.1 | Fixed in 4.21.1 | 29 Aug 2026 |
| Broken access control CVE-2026-18233 | Medium 6.5 | Before 4.21.1 | Fixed in 4.21.1 | 29 Aug 2026 |
| Broken access control CVE-2026-16039 | Medium 6.5 | Before 4.21.0 | Fixed in 4.21.0 | 7 Aug 2026 |
| Broken access control CVE-2026-16041 | High 7.5 | Before 4.21.0 | Fixed in 4.21.0 | 7 Aug 2026 |
| Authentication bypass CVE-2026-16030 | High 8.1 | Before 4.21.0 | Fixed in 4.21.0 | 7 Aug 2026 |
| Broken access control CVE-2026-16038 | Critical 9.1 | Before 4.21.0 | Fixed in 4.21.0 | 7 Aug 2026 |
| Remote code execution CVE-2021-47933 | Critical 9.8 | Not yet published | Check for an update | 10 May 2026 |
| Cross-site scripting (XSS) CVE-2026-3568 | Medium 4.3 | Up to 4.18.3 | Fixed in a later version (latest 4.22.1) | 9 Apr 2026 |
| Broken access control CVE-2025-4683 | Medium 4.3 | Before 4.17.6 | Fixed in 4.17.6 | 27 May 2025 |
| Privilege escalation CVE-2025-3438 | Medium 6.5 | Before 4.17.5 | Fixed in 4.17.5 | 2 May 2025 |
| Cross-site scripting (XSS) CVE-2024-12042 | Medium 5.4 | Before 4.16.5 | Fixed in 4.16.5 | 13 Dec 2024 |
| SQL injection CVE-2024-11179 | Medium 6.5 | Before 4.15.8 | Fixed in 4.15.8 | 20 Nov 2024 |
| Broken access control CVE-2024-8269 | High 7.3 | Before 4.15.4 | Fixed in 4.15.4 | 13 Sep 2024 |
| Remote code execution CVE-2024-8242 | Medium 4.3 | Before 4.15.4 | Fixed in 4.15.4 | 13 Sep 2024 |
| Authentication bypass CVE-2024-7628 | High 8.1 | Before 4.15.3 | Fixed in 4.15.3 | 15 Aug 2024 |
| Authentication bypass CVE-2024-6328 | Critical 9.8 | Before 4.15.0 | Fixed in 4.15.0 | 12 Jul 2024 |
| Privilege escalation CVE-2023-3277 | Critical 9.8 | Up to 4.10.7 | Fixed in a later version (latest 4.22.1) | 3 Nov 2023 |
| Cross-site request forgery (CSRF) CVE-2023-3199 | Medium 4.3 | Up to 3.9.6 | Fixed in a later version (latest 4.22.1) | 12 Jul 2023 |
| Cross-site request forgery (CSRF) CVE-2023-3202 | Medium 4.3 | Up to 3.9.6 | Fixed in a later version (latest 4.22.1) | 12 Jul 2023 |
| Security weakness CVE-2023-3131 | Medium 4.3 | Before 3.9.7 | Fixed in 3.9.7 | 10 Jul 2023 |
| Security weakness CVE-2023-3209 | Low 3.5 | Before 3.9.7 | Fixed in 3.9.7 | 10 Jul 2023 |
| Broken access control CVE-2023-3076 | Critical 9.8 | Before 3.9.9 | Fixed in 3.9.9 | 10 Jul 2023 |
| SQL injection CVE-2023-3077 | Critical 9.8 | Before 3.9.8 | Fixed in 3.9.8 | 10 Jul 2023 |
| SQL injection CVE-2023-3197 | Critical 9.8 | Up to 4.0.1 | Fixed in a later version (latest 4.22.1) | 24 Jun 2023 |
| Cross-site request forgery (CSRF) CVE-2023-3198 | Medium 4.3 | Up to 3.9.6 | Fixed in a later version (latest 4.22.1) | 14 Jun 2023 |
| Cross-site request forgery (CSRF) CVE-2023-3200 | Medium 4.3 | Up to 3.9.6 | Fixed in a later version (latest 4.22.1) | 14 Jun 2023 |
| Cross-site request forgery (CSRF) CVE-2023-3201 | Medium 4.3 | Up to 3.9.6 | Fixed in a later version (latest 4.22.1) | 14 Jun 2023 |
| Cross-site request forgery (CSRF) CVE-2023-3203 | Medium 4.3 | Up to 3.9.6 | Fixed in a later version (latest 4.22.1) | 14 Jun 2023 |
| Authentication bypass CVE-2020-36713 | Critical 9.8 | Up to 2.1.5 | Fixed in a later version (latest 4.22.1) | 7 Jun 2023 |
| Authentication bypass CVE-2023-2732 | Critical 9.8 | Up to 3.9.2 | Fixed in a later version (latest 4.22.1) | 25 May 2023 |
| Authentication bypass CVE-2023-2733 | Critical 9.8 | Up to 3.9.0 | Fixed in a later version (latest 4.22.1) | 25 May 2023 |
| Authentication bypass CVE-2023-2734 | Critical 9.8 | Up to 3.9.1 | Fixed in a later version (latest 4.22.1) | 25 May 2023 |
| Authentication bypass CVE-2021-24148 | Critical 9.8 | Before 3.2.0 | Fixed in 3.2.0 | 18 Mar 2021 |
Read the published descriptions
- CVE-2026-97219, 2 Oct 2026
- The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying. CVE record
- CVE-2026-13447, 5 Sep 2026
- The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to forge a Firebase Phone Auth JWT signed with a self-generated RSA key pair and impersonate any phone number, resulting in unauthorized access to existing WordPress accounts or creation of new arbitrary accounts. CVE record
- CVE-2026-18234, 29 Aug 2026
- The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment being taken. CVE record
- CVE-2026-18233, 29 Aug 2026
- The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as completed and paid without any payment being made. CVE record
- CVE-2026-16039, 7 Aug 2026
- The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information. CVE record
- CVE-2026-16041, 7 Aug 2026
- The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners. CVE record
- CVE-2026-16030, 7 Aug 2026
- The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. CVE record
- CVE-2026-16038, 7 Aug 2026
- The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free. CVE record
- CVE-2021-47933, 10 May 2026
- WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server. CVE record
- CVE-2026-3568, 9 Apr 2026
- The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist, blocklist, or validation of meta keys. The function reads raw JSON from php://input (line 1012), decodes it (line 1013), authenticates the user via cookie validation (line 1015), and then directly iterates over the user-supplied meta_data array passing arbitrary keys and values to update_user_meta() (line 1080) with no sanitization or restrictions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary user meta fields on their own accounts, including sensitive fields like wp_user_level (to escalate to administrator-level legacy checks), plugin-specific authorization flags (e.g., _wpuf_user_active, aiowps_account_status), and billing/profile fields with unsanitized values (potentially enabling Stored XSS in admin contexts). Note that wp_capabilities cannot be directly exploited this way because it requires a serialized array value, but wp_user_level (a simple integer) and numerous plugin-specific meta keys are exploitable. CVE record
- CVE-2025-4683, 27 May 2025
- The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new posts. CVE record
- CVE-2025-3438, 2 May 2025
- The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering. This makes it possible for unauthenticated attackers to to register with the 'wcfm_vendor' role, which is a Store Vendor role in the WCFM Marketplace - Multivendor Marketplace for WooCommerce plugin for WordPress. The vulnerability can only be exploited if the WCFM Marketplace - Multivendor Marketplace for WooCommerce plugin is installed and activated. The vulnerability was partially patched in version 4.17.3. CVE record
- CVE-2024-12042, 13 Dec 2024
- The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload HTML files with arbitrary web scripts that will execute whenever a user accesses the file. CVE record
- CVE-2024-11179, 20 Nov 2024
- The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2024-8269, 13 Sep 2024
- The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function. This makes it possible for unauthenticated attackers to create user accounts on sites, even when user registration is disabled and plugin functionality is not activated. CVE record
- CVE-2024-8242, 13 Sep 2024
- The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up to, and including, 4.15.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files (not including PHP files) on the affected site's server which may make remote code execution possible. This can be paired with a registration endpoint for unauthenticated users to exploit the issue. CVE record
- CVE-2024-7628, 15 Aug 2024
- The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in the 'verify_id_token' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to an @flutter.io email address or phone number. This also requires firebase to be configured on the website and the user to have set up firebase for their account. CVE record
- CVE-2024-6328, 12 Jul 2024
- The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and 'firebase_sms_login_v2' functions. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email address or phone number. Additionally, if a new email address is supplied, a new user account is created with the default role, even if registration is disabled. CVE record
- CVE-2023-3277, 3 Nov 2023
- The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address. CVE record
- CVE-2023-3199, 12 Jul 2023
- The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_title function. This makes it possible for unauthenticated attackers to update status order title via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2023-3202, 12 Jul 2023
- The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenticated attackers to update the firebase server key to push notification when order status changed via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2023-3131, 10 Jul 2023
- The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both. CVE record
- CVE-2023-3209, 10 Jul 2023
- The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both. CVE record
- CVE-2023-3076, 10 Jul 2023
- The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features. CVE record
- CVE-2023-3077, 10 Jul 2023
- The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocommerce-appointments plugin. CVE record
- CVE-2023-3197, 24 Jun 2023
- The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2023-3198, 14 Jun 2023
- The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_message function. This makes it possible for unauthenticated attackers to update status order message via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2023-3200, 14 Jun 2023
- The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_message function. This makes it possible for unauthenticated attackers to update new order message via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2023-3201, 14 Jun 2023
- The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticated attackers to update new order title via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2023-3203, 14 Jun 2023
- The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_limit_product function. This makes it possible for unauthenticated attackers to update limit the number of product per category to use cache data in home screen via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2020-36713, 7 Jun 2023
- The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated attackers to create new administrator accounts, delete existing administrator accounts, or escalate privileges on any account. CVE record
- CVE-2023-2732, 25 May 2023
- The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. CVE record
- CVE-2023-2733, 25 May 2023
- The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. CVE record
- CVE-2023-2734, 25 May 2023
- The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. CVE record
- CVE-2021-24148, 18 Mar 2021
- A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address. CVE record
What to do if you run MStore API
If you run MStore API, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new MStore API vulnerabilities
Free. We email you when a new vulnerability is published for MStore API, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.