cleantalk
Vulnerabilities and Security Researches

MStore API, CVE-2023-3076

CVE, Research URL

CVE-2023-3076

Application

MStore API

Published on
Jul 10, 2023
Research Description
The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.
Affected versions
Min -, max 3.9.9.
Status
vulnerable