Access violation vulnerability in MStore API – Create Native Android & iOS Apps On The Cloud 4.17.4

A plugin called MStore API, which helps create mobile apps for WordPress, has a security issue. This issue allows attackers to gain higher privileges and access certain features without proper authentication. The issue affects all versions up to 4.17.4 and can only be exploited if another plugin called WCFM Marketplace is also installed and activated. The company has released a partial fix in version 4.17.3.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.