Input validation vulnerability in MStore API 3.9.6

The MStore API plugin for WordPress has a security vulnerability that allows unauthenticated attackers to change the firebase server key for push notifications when an order status changes. This could happen if an attacker tricked an administrator into clicking a malicious link. To prevent this from happening, the plugin needs to have nonce validation added to its mstore_update_firebase_server_key function.

Detected in:

MStore API fixed vulnerable versions: >= * <= 3.9.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.