Access violation vulnerability in MStore API – Create Native Android & iOS Apps On The Cloud 4.15.3

The MStore API plugin for WordPress allows users to create native Android and iOS apps on the cloud. However, it has a security issue where unauthorized users can register for an account on any version up to 4.15.3. The problem is that the plugin does not check if user registration is enabled before creating a new account using the register() function. This means that anyone, even without proper authentication, can create an account on a site, even if user registration is turned off and the plugin is not active.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.