Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesMStore API

MStore API vulnerabilities

MStore API has 35 known vulnerabilities in this database. The most recent published record is dated 2 Oct 2026.

Known vulnerabilities
35
Active installs
2,000+
Latest version
4.22.1
Last updated
29 Sep 2026
Most recent
2 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Broken access control
CVE-2026-97219
Medium 4.3Before 4.22.1Fixed in 4.22.15 d ago
Authentication bypass
CVE-2026-13447
Critical 9.8Up to 4.20.0Fixed in a later version (latest 4.22.1)5 Sep 2026
Broken access control
CVE-2026-18234
Medium 6.5Before 4.21.1Fixed in 4.21.129 Aug 2026
Broken access control
CVE-2026-18233
Medium 6.5Before 4.21.1Fixed in 4.21.129 Aug 2026
Broken access control
CVE-2026-16039
Medium 6.5Before 4.21.0Fixed in 4.21.07 Aug 2026
Broken access control
CVE-2026-16041
High 7.5Before 4.21.0Fixed in 4.21.07 Aug 2026
Authentication bypass
CVE-2026-16030
High 8.1Before 4.21.0Fixed in 4.21.07 Aug 2026
Broken access control
CVE-2026-16038
Critical 9.1Before 4.21.0Fixed in 4.21.07 Aug 2026
Remote code execution
CVE-2021-47933
Critical 9.8Not yet publishedCheck for an update10 May 2026
Cross-site scripting (XSS)
CVE-2026-3568
Medium 4.3Up to 4.18.3Fixed in a later version (latest 4.22.1)9 Apr 2026
Broken access control
CVE-2025-4683
Medium 4.3Before 4.17.6Fixed in 4.17.627 May 2025
Privilege escalation
CVE-2025-3438
Medium 6.5Before 4.17.5Fixed in 4.17.52 May 2025
Cross-site scripting (XSS)
CVE-2024-12042
Medium 5.4Before 4.16.5Fixed in 4.16.513 Dec 2024
SQL injection
CVE-2024-11179
Medium 6.5Before 4.15.8Fixed in 4.15.820 Nov 2024
Broken access control
CVE-2024-8269
High 7.3Before 4.15.4Fixed in 4.15.413 Sep 2024
Remote code execution
CVE-2024-8242
Medium 4.3Before 4.15.4Fixed in 4.15.413 Sep 2024
Authentication bypass
CVE-2024-7628
High 8.1Before 4.15.3Fixed in 4.15.315 Aug 2024
Authentication bypass
CVE-2024-6328
Critical 9.8Before 4.15.0Fixed in 4.15.012 Jul 2024
Privilege escalation
CVE-2023-3277
Critical 9.8Up to 4.10.7Fixed in a later version (latest 4.22.1)3 Nov 2023
Cross-site request forgery (CSRF)
CVE-2023-3199
Medium 4.3Up to 3.9.6Fixed in a later version (latest 4.22.1)12 Jul 2023
Cross-site request forgery (CSRF)
CVE-2023-3202
Medium 4.3Up to 3.9.6Fixed in a later version (latest 4.22.1)12 Jul 2023
Security weakness
CVE-2023-3131
Medium 4.3Before 3.9.7Fixed in 3.9.710 Jul 2023
Security weakness
CVE-2023-3209
Low 3.5Before 3.9.7Fixed in 3.9.710 Jul 2023
Broken access control
CVE-2023-3076
Critical 9.8Before 3.9.9Fixed in 3.9.910 Jul 2023
SQL injection
CVE-2023-3077
Critical 9.8Before 3.9.8Fixed in 3.9.810 Jul 2023
SQL injection
CVE-2023-3197
Critical 9.8Up to 4.0.1Fixed in a later version (latest 4.22.1)24 Jun 2023
Cross-site request forgery (CSRF)
CVE-2023-3198
Medium 4.3Up to 3.9.6Fixed in a later version (latest 4.22.1)14 Jun 2023
Cross-site request forgery (CSRF)
CVE-2023-3200
Medium 4.3Up to 3.9.6Fixed in a later version (latest 4.22.1)14 Jun 2023
Cross-site request forgery (CSRF)
CVE-2023-3201
Medium 4.3Up to 3.9.6Fixed in a later version (latest 4.22.1)14 Jun 2023
Cross-site request forgery (CSRF)
CVE-2023-3203
Medium 4.3Up to 3.9.6Fixed in a later version (latest 4.22.1)14 Jun 2023
Authentication bypass
CVE-2020-36713
Critical 9.8Up to 2.1.5Fixed in a later version (latest 4.22.1)7 Jun 2023
Authentication bypass
CVE-2023-2732
Critical 9.8Up to 3.9.2Fixed in a later version (latest 4.22.1)25 May 2023
Authentication bypass
CVE-2023-2733
Critical 9.8Up to 3.9.0Fixed in a later version (latest 4.22.1)25 May 2023
Authentication bypass
CVE-2023-2734
Critical 9.8Up to 3.9.1Fixed in a later version (latest 4.22.1)25 May 2023
Authentication bypass
CVE-2021-24148
Critical 9.8Before 3.2.0Fixed in 3.2.018 Mar 2021
Read the published descriptions
CVE-2026-97219, 2 Oct 2026
The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying. CVE record
CVE-2026-13447, 5 Sep 2026
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to forge a Firebase Phone Auth JWT signed with a self-generated RSA key pair and impersonate any phone number, resulting in unauthorized access to existing WordPress accounts or creation of new arbitrary accounts. CVE record
CVE-2026-18234, 29 Aug 2026
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment being taken. CVE record
CVE-2026-18233, 29 Aug 2026
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as completed and paid without any payment being made. CVE record
CVE-2026-16039, 7 Aug 2026
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information. CVE record
CVE-2026-16041, 7 Aug 2026
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners. CVE record
CVE-2026-16030, 7 Aug 2026
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. CVE record
CVE-2026-16038, 7 Aug 2026
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free. CVE record
CVE-2021-47933, 10 May 2026
WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server. CVE record
CVE-2026-3568, 9 Apr 2026
The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist, blocklist, or validation of meta keys. The function reads raw JSON from php://input (line 1012), decodes it (line 1013), authenticates the user via cookie validation (line 1015), and then directly iterates over the user-supplied meta_data array passing arbitrary keys and values to update_user_meta() (line 1080) with no sanitization or restrictions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary user meta fields on their own accounts, including sensitive fields like wp_user_level (to escalate to administrator-level legacy checks), plugin-specific authorization flags (e.g., _wpuf_user_active, aiowps_account_status), and billing/profile fields with unsanitized values (potentially enabling Stored XSS in admin contexts). Note that wp_capabilities cannot be directly exploited this way because it requires a serialized array value, but wp_user_level (a simple integer) and numerous plugin-specific meta keys are exploitable. CVE record
CVE-2025-4683, 27 May 2025
The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new posts. CVE record
CVE-2025-3438, 2 May 2025
The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering. This makes it possible for unauthenticated attackers to to register with the 'wcfm_vendor' role, which is a Store Vendor role in the WCFM Marketplace - Multivendor Marketplace for WooCommerce plugin for WordPress. The vulnerability can only be exploited if the WCFM Marketplace - Multivendor Marketplace for WooCommerce plugin is installed and activated. The vulnerability was partially patched in version 4.17.3. CVE record
CVE-2024-12042, 13 Dec 2024
The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload HTML files with arbitrary web scripts that will execute whenever a user accesses the file. CVE record
CVE-2024-11179, 20 Nov 2024
The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2024-8269, 13 Sep 2024
The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function. This makes it possible for unauthenticated attackers to create user accounts on sites, even when user registration is disabled and plugin functionality is not activated. CVE record
CVE-2024-8242, 13 Sep 2024
The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up to, and including, 4.15.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files (not including PHP files) on the affected site's server which may make remote code execution possible. This can be paired with a registration endpoint for unauthenticated users to exploit the issue. CVE record
CVE-2024-7628, 15 Aug 2024
The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in the 'verify_id_token' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to an @flutter.io email address or phone number. This also requires firebase to be configured on the website and the user to have set up firebase for their account. CVE record
CVE-2024-6328, 12 Jul 2024
The MStore API - Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and 'firebase_sms_login_v2' functions. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email address or phone number. Additionally, if a new email address is supplied, a new user account is created with the default role, even if registration is disabled. CVE record
CVE-2023-3277, 3 Nov 2023
The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address. CVE record
CVE-2023-3199, 12 Jul 2023
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_title function. This makes it possible for unauthenticated attackers to update status order title via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2023-3202, 12 Jul 2023
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenticated attackers to update the firebase server key to push notification when order status changed via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2023-3131, 10 Jul 2023
The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both. CVE record
CVE-2023-3209, 10 Jul 2023
The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both. CVE record
CVE-2023-3076, 10 Jul 2023
The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features. CVE record
CVE-2023-3077, 10 Jul 2023
The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocommerce-appointments plugin. CVE record
CVE-2023-3197, 24 Jun 2023
The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2023-3198, 14 Jun 2023
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_message function. This makes it possible for unauthenticated attackers to update status order message via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2023-3200, 14 Jun 2023
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_message function. This makes it possible for unauthenticated attackers to update new order message via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2023-3201, 14 Jun 2023
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticated attackers to update new order title via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2023-3203, 14 Jun 2023
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_limit_product function. This makes it possible for unauthenticated attackers to update limit the number of product per category to use cache data in home screen via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2020-36713, 7 Jun 2023
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated attackers to create new administrator accounts, delete existing administrator accounts, or escalate privileges on any account. CVE record
CVE-2023-2732, 25 May 2023
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. CVE record
CVE-2023-2733, 25 May 2023
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. CVE record
CVE-2023-2734, 25 May 2023
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. CVE record
CVE-2021-24148, 18 Mar 2021
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address. CVE record

What to do if you run MStore API

If you run MStore API, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new MStore API vulnerabilities

Free. We email you when a new vulnerability is published for MStore API, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support