Input validation vulnerability in MStore API – Create Native Android & iOS Apps On The Cloud 4.15.3

The MStore API plugin for WordPress allows users to create mobile apps for Android and iOS on the cloud. However, it has a security vulnerability that allows someone with certain access levels to upload any type of file (except PHP files) to the website’s server. This could potentially lead to someone being able to execute code on the site. Unauthenticated users could also exploit this issue through a registration endpoint.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.