Authentication vulnerability in MStore API 2.1.6

MStore API is a plugin for WordPress websites that has a security issue in versions up to and including 2.1.5. This security issue allows anyone to access certain parts of the plugin without being authenticated (logged in). This means that attackers can create new administrator accounts, delete existing administrator accounts, or change privileges on any account, without being granted permission.

Detected in:

MStore API fixed vulnerable versions: >= * < 2.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.