Input validation vulnerability in MStore API 4.10.1

The MStore API plugin for WordPress has a vulnerability that could allow unauthenticated attackers to upload an Apple key file. This vulnerability affects all versions of the plugin up to version 4.10.2 and is caused by incorrect or missing nonce validation in the ‘templates/admin/mstore-api-admin-dashboard.php’ file. To exploit this vulnerability, an attacker would need to trick a site administrator into performing an action such as clicking on a malicious link. To protect against this vulnerability, users should update the MStore API plugin for WordPress to the latest version.

Detected in:

MStore API fixed vulnerable versions: >= * <= 4.10.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.