Inspireui

Mstore Api

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 14.06.2023 02:15:08
  • Zuletzt bearbeitet 21.11.2024 08:16:41

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticated attackers to update new order title via a forged...

  • EPSS 0.07%
  • Veröffentlicht 14.06.2023 02:15:08
  • Zuletzt bearbeitet 21.11.2024 08:16:40

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_message function. This makes it possible for unauthenticated attackers to update new order message via a fo...

  • EPSS 0.1%
  • Veröffentlicht 14.06.2023 02:15:08
  • Zuletzt bearbeitet 21.11.2024 08:16:40

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_message function. This makes it possible for unauthenticated attackers to update status order message vi...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 07.06.2023 02:15:11
  • Zuletzt bearbeitet 21.11.2024 05:30:08

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated atta...

  • EPSS 60.34%
  • Veröffentlicht 25.05.2023 03:15:08
  • Zuletzt bearbeitet 21.11.2024 07:59:11

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plug...

  • EPSS 0.3%
  • Veröffentlicht 25.05.2023 03:15:08
  • Zuletzt bearbeitet 21.11.2024 07:59:11

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. ...

  • EPSS 90%
  • Veröffentlicht 25.05.2023 03:15:08
  • Zuletzt bearbeitet 21.11.2024 07:59:11

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This m...

  • EPSS 5.63%
  • Veröffentlicht 18.03.2021 15:15:15
  • Zuletzt bearbeitet 21.11.2024 05:52:28

A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.