MStore API

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in MStore API 4.10.1

    Fixed

    The MStore API plugin for WordPress has a vulnerability that could allow unauthenticated attackers to upload an Apple key file. This vulnerability affects all versions of the plugin up to version 4.1...

    Read More
  • Authentication vulnerability in MStore API 4.10.7

    Fixed

    The MStore API plugin for WordPress is a software that has a security flaw. Unauthorized people can gain access to user accounts and be granted more privileges than they should have if they know the ...

    Read More
  • Input validation vulnerability in MStore API 4.0.6

    Fixed

    The MStore API plugin for WordPress is not secure in versions up to and including 4.0.6. This plugin allows people with certain levels of access to get sensitive information from the database. This i...

    Read More
  • Input validation vulnerability in MStore API 3.9.7

    Fixed

    The MStore API plugin for WordPress is vulnerable to an attack where unauthorized users can see information from the database without permission. This is possible because the plugin's security measur...

    Read More
  • Input validation vulnerability in MStore API 3.9.7

    Fixed

    The MStore API plugin for WordPress is a tool that has a security flaw that can be used to access sensitive information from a database. In versions up to 3.9.7, this plugin does not properly escape ...

    Read More
  • Access violation vulnerability in MStore API 3.9.8

    Fixed

    The MStore API plugin for WordPress is vulnerable to a security issue in versions 3.9.8 and earlier. This issue allows any unauthenticated user to register to the website as an administrator, without...

    Read More
  • Input validation vulnerability in MStore API 4.0.1

    Fixed

    The MStore API plugin for WordPress is vulnerable to a type of attack called "Unauthenticated Blind SQL Injection". This means that in versions of the plugin up to and including 4.0.1, people who are...

    Read More
  • Input validation vulnerability in MStore API 3.9.7

    Fixed

    The MStore API plugin for WordPress has a security vulnerability in versions up to 3.9.7. This vulnerability allows unauthenticated attackers to inject malicious code into the database, which can be ...

    Read More
  • Input validation vulnerability in MStore API 3.9.6

    Fixed

    The MStore API plugin for WordPress has a security vulnerability that allows unauthenticated attackers to change the firebase server key for push notifications when an order status changes. This coul...

    Read More
  • Input validation vulnerability in MStore API 3.9.6

    Fixed

    The MStore API plugin for WordPress has a security issue that makes it vulnerable to Cross-Site Request Forgery. This means that if an attacker could deceive an administrator into clicking a link, th...

    Read More
  • Input validation vulnerability in MStore API 3.9.6

    Fixed

    The MStore API plugin for WordPress has a security flaw that allows unauthenticated attackers to alter the status order message. This happens when a site administrator clicks a link that has been sen...

    Read More
  • Input validation vulnerability in MStore API 3.9.6

    Fixed

    The MStore API plugin for WordPress is potentially vulnerable to a security issue. An attacker could potentially use a forged request to update status order titles. This could occur if they can get a...

    Read More
  • Input validation vulnerability in MStore API 3.9.6

    Fixed

    The MStore API plugin for WordPress has a security vulnerability that could be exploited by unauthenticated attackers. This vulnerability makes it possible for attackers to update the new order messa...

    Read More
  • Input validation vulnerability in MStore API 3.9.6

    Fixed

    The MStore API plugin for WordPress has a security vulnerability that could allow unauthenticated attackers to update the amount of products that are shown in the home screen. This could be done by t...

    Read More
  • Access violation vulnerability in MStore API 3.9.6

    Fixed

    The MStore API plugin for WordPress can be manipulated by attackers with minimal permissions (even a subscriber) to change the plugin's settings without authorization. This vulnerability was found in...

    Read More
  • Authentication vulnerability in MStore API 3.9.2

    Fixed

    The MStore API plugin for WordPress is a tool that can be used to add listings to a WordPress website. Unfortunately, versions up to and including 3.9.2 are vulnerable to a security issue. This means...

    Read More
  • Authentication vulnerability in MStore API 3.9.0

    Fixed

    The MStore API plugin for WordPress is not secure in versions 3.9.0 and below. This means that if someone knows the ID of an existing user, such as an administrator, they can gain access to that user...

    Read More
  • Authentication vulnerability in MStore API 3.9.1

    Fixed

    The MStore API WordPress plugin, up to version 3.9.1, has a security issue where unauthenticated attackers can gain access to the site as an existing user, such as an administrator, as long as they h...

    Read More
  • Authentication vulnerability in MStore API 2.1.6

    Fixed

    MStore API is a plugin for WordPress websites that has a security issue in versions up to and including 2.1.5. This security issue allows anyone to access certain parts of the plugin without being au...

    Read More
  • Authentication vulnerability in MStore API 3.1.9

    Fixed

    A problem with the MStore API WordPress plugin

    Read More
  • Input validation vulnerability in MStore API 3.4.5

    Fixed

    The MStore API plugin for WordPress has a security issue in versions before 3.4.5. It does not have authorization protection for the api/flutter_woo/config_file REST endpoint. This means that people ...

    Read More