Mstore Api

WordPress plugin · mstore-api · WordPress.org ↗
1
Critical
2
High
6
Known total
0
Unfixed
Running Mstore Api on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
CRITICAL
CVSS 9.1
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
CVE.org
>=0, <4.21.0 v4.21.0 CVE-2026-16038 Aug 7, 2026
HIGH
CVSS 8.1
MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
CVE.org
>=0, <4.21.0 v4.21.0 CVE-2026-16030 Aug 7, 2026
HIGH
CVSS 7.5
MStore API < 4.21.0 - Unauthenticated Product Review Creation
CVE.org
>=0, <4.21.0 v4.21.0 CVE-2026-16041 Aug 7, 2026
MEDIUM
CVSS 6.5
MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet
CVE.org
>=0, <4.21.1 v4.21.1 CVE-2026-18234 Aug 29, 2026
MEDIUM
CVSS 6.5
MStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion
CVE.org
>=0, <4.21.1 v4.21.1 CVE-2026-18233 Aug 29, 2026
MEDIUM
CVSS 6.5
MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR
CVE.org
>=0, <4.21.0 v4.21.0 CVE-2026-16039 Aug 7, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.