← WordPress Vulnerabilities
WordPress security by component

MStore API

MStore API is a WordPress component with 32 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: mstore-api

CVE-2026-57375: MStore API: A security weakness

MStore API is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.18.4.

PublishedJul 13, 2026
Known safe version4.19.0
Safe version
Jul 13, 2026 CVE-2026-57375
MStore API: A security weakness
MStore API is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.18.4.
4.19.0
CVE6.5
NVDPending
Jun 17, 2026 CVE-2026-54817
MStore API: Privilege escalation or authentication bypass
MStore API is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 4.18.4.
4.19.0
CVE6.5
NVDPending
May 10, 2026 CVE-2021-47933
MStore API: Dangerous file upload
MStore API is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is 2.0.6.
See mitigation notes
CVE9.3
NVDPending
Apr 09, 2026 CVE-2026-3568
MStore API – Create Native Android & iOS Apps On The Cloud: Cross-site scripting
MStore API – Create Native Android & iOS Apps On The Cloud is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 4.18.3.
> 4.18.3
CVE4.3
NVDPending
May 27, 2025 CVE-2025-4683
MStore API – Create Native Android & iOS Apps On The Cloud: A security weakness
MStore API – Create Native Android & iOS Apps On The Cloud is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
May 02, 2025 CVE-2025-3438
MStore API – Create Native Android & iOS Apps On The Cloud: Privilege escalation or authentication bypass
MStore API – Create Native Android & iOS Apps On The Cloud is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE6.5
NVD7.3
Dec 13, 2024 CVE-2024-12042
MStore API – Create Native Android & iOS Apps On The Cloud: Cross-site scripting
MStore API – Create Native Android & iOS Apps On The Cloud is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Nov 20, 2024 CVE-2024-11179
MStore API – Create Native Android & iOS Apps On The Cloud: SQL injection
MStore API – Create Native Android & iOS Apps On The Cloud is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVDPending
Sep 13, 2024 CVE-2024-8269
MStore API – Create Native Android & iOS Apps On The Cloud: A security weakness
MStore API – Create Native Android & iOS Apps On The Cloud is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVD6.5
Sep 13, 2024 CVE-2024-8242
MStore API – Create Native Android & iOS Apps On The Cloud: Dangerous file upload
MStore API – Create Native Android & iOS Apps On The Cloud is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE4.3
NVD8.8
Aug 15, 2024 CVE-2024-7628
MStore API – Create Native Android & iOS Apps On The Cloud: Privilege escalation or authentication bypass
MStore API – Create Native Android & iOS Apps On The Cloud is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVDPending
Jul 12, 2024 CVE-2024-6328
MStore API – Create Native Android & iOS Apps On The Cloud: Privilege escalation or authentication bypass
MStore API – Create Native Android & iOS Apps On The Cloud is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Dec 29, 2023 CVE-2023-50878
MStore API: Cross-site request forgery
MStore API is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Nov 06, 2023 CVE-2023-45055
MStore API: SQL injection
MStore API is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVD9.8
Nov 03, 2023 CVE-2023-3277
MStore API: Privilege escalation or authentication bypass
MStore API is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8
Jul 12, 2023 CVE-2023-3202
MStore API: Cross-site request forgery
MStore API is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Jul 12, 2023 CVE-2023-3199
MStore API: Cross-site request forgery
MStore API is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Jul 10, 2023 CVE-2023-3209
MStore API: A security weakness
MStore API is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.5
NVD3.5
Jul 10, 2023 CVE-2023-3131
MStore API: A security weakness
MStore API is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Jul 10, 2023 CVE-2023-3077
MStore API: SQL injection
MStore API is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Jul 10, 2023 CVE-2023-3076
MStore API: A security weakness
MStore API is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Jun 24, 2023 CVE-2023-3197
MStore API: SQL injection
MStore API is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVDPending
Jun 23, 2023 CVE-2022-47614
Mstore Api: SQL injection
Mstore Api is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5
Jun 14, 2023 CVE-2023-3203
MStore API: Cross-site request forgery
MStore API is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jun 14, 2023 CVE-2023-3201
MStore API: Cross-site request forgery
MStore API is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jun 14, 2023 CVE-2023-3200
MStore API: Cross-site request forgery
MStore API is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jun 14, 2023 CVE-2023-3198
MStore API: Cross-site request forgery
MStore API is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jun 07, 2023 CVE-2020-36713
MStore API: Privilege escalation or authentication bypass
MStore API is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8
May 25, 2023 CVE-2023-2734
MStore API: Privilege escalation or authentication bypass
MStore API is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8
May 25, 2023 CVE-2023-2733
MStore API: Privilege escalation or authentication bypass
MStore API is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8
May 25, 2023 CVE-2023-2732
MStore API: Privilege escalation or authentication bypass
MStore API is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8
Mar 18, 2021 CVE-2021-24148
MStore API: Privilege escalation or authentication bypass
MStore API is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8