Input validation vulnerability in MStore API 3.4.5

The MStore API plugin for WordPress has a security issue in versions before 3.4.5. It does not have authorization protection for the api/flutter_woo/config_file REST endpoint. This means that people who are not authorized to do so can upload files to the server of websites using these versions of the plugin. These files could potentially allow the attacker to run malicious code on the affected website.

Detected in:

MStore API fixed vulnerable versions: >= * < 3.4.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.