cleantalk
Vulnerabilities and Security Researches

MStore API, 6d230f3173dc0c1c7698859557af2d7a08437bac

Application

MStore API

Published on
Jun 12, 2023
Research Description
MStore API &#8211; Create Native Android &amp; iOS Apps On The Cloud [mstore-api] < 3.9.6 MStore API <= 3.9.6 - Missing Authorization The MStore API plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions called via AJAX actions such as mstore_delete_json_file, mstore_update_limit_product, mstore_update_firebase_server_key, mstore_update_new_order_title, mstore_update_new_order_message, mstore_update_status_order_title, and mstore_update_status_order_message in versions up to, and including, 3.9.6. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to perform several unauthorized actions that allow the attacker to control the plugins settings. This was partially patched in 3.9.6 but not fully patched until 3.9.7. CVE-2023-3209 Also applies to this vulnerability.
Affected versions
max 3.9.6.
Status
vulnerable