📦 Mstore Api

by Inspireui

🔍 What is Mstore Api?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-6328

CRITICAL CVSS 9.8 Jul 12, 2024

The MStore API WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user by exploiting insufficient verification of the 'phone' p...

CVE-2023-45055

CRITICAL CVSS 9.8 Nov 6, 2023

This SQL injection vulnerability in the InspireUI MStore API WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affects all WordPress sites using MStore API versio...

CVE-2023-3277

CRITICAL CVSS 9.8 Nov 3, 2023

The MStore API WordPress plugin has an authentication bypass vulnerability in its Apple login feature. Unauthenticated attackers can log in as any user by knowing their email address, leading to unaut...

CVE-2023-3077

CRITICAL CVSS 9.8 Jul 10, 2023

This vulnerability allows unauthenticated attackers to perform blind SQL injection attacks on WordPress sites using the MStore API plugin before version 3.9.8. The attack is only possible if the site ...

CVE-2020-36713

CRITICAL CVSS 9.8 Jun 7, 2023

The MStore API WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to create administrator accounts, delete existing admin accounts, or escalate privilege...

CVE-2023-2732

CRITICAL CVSS 9.8 May 25, 2023

The MStore API plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user, including administrators, by exploiting insufficien...

CVE-2023-2734

CRITICAL CVSS 9.8 May 25, 2023

The MStore API WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user, including administrators, by exploiting insufficient ve...

CVE-2021-24148

CRITICAL CVSS 9.8 Mar 18, 2021

This vulnerability allows unauthenticated attackers to bypass authentication in the MStore API WordPress plugin by exploiting a business logic flaw in the Sign In With Apple feature. Attackers can rec...

CVE-2024-8269

HIGH CVSS 7.3 Sep 13, 2024

The MStore API WordPress plugin allows unauthenticated attackers to create user accounts even when user registration is disabled. This affects all WordPress sites using MStore API plugin versions up t...

CVE-2022-47614

HIGH CVSS 7.5 Jun 23, 2023

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against WordPress sites using the InspireUI MStore API plugin. Attackers can execute arbitrary SQL commands, potent...

CVE-2025-4683

MEDIUM CVSS 4.3 May 27, 2025

The MStore API WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level permissions or higher to create new posts without proper authorization. This af...

CVE-2025-3438

MEDIUM CVSS 6.5 May 2, 2025

The MStore API WordPress plugin allows unauthenticated attackers to register accounts with 'wcfm_vendor' privileges when the WCFM Marketplace plugin is active. This enables limited privilege escalatio...

CVE-2024-12042

MEDIUM CVSS 5.4 Dec 13, 2024

The MStore API WordPress plugin has a stored XSS vulnerability in profile picture upload functionality. Authenticated attackers with subscriber-level access can upload malicious HTML files that execut...

CVE-2024-11179

MEDIUM CVSS 6.5 Nov 20, 2024

This SQL injection vulnerability in the MStore API WordPress plugin allows authenticated attackers with Subscriber-level access or higher to inject malicious SQL queries via the 'status_type' paramete...