Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.18% | — | Inspireui Mstore APIAI | 2/10/2026 | 2/10/2026 | The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying. | |
| Aplazada | Crítica (9.8) | 0.45% | — | Inspireui Mstore APIAI | 5/9/2026 | 8/9/2026 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid,… | |
| Aplazada | Media (6.5) | 0.17% | — | Inspireui Mstore APIAI | 29/8/2026 | 31/8/2026 | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment… | |
| Aplazada | Media (6.5) | 0.17% | — | Inspireui Mstore APIAI | 29/8/2026 | 31/8/2026 | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as completed and paid without any payment being made. | |
| Aplazada | Alta (8.1) | 0.37% | — | Inspireui Mstore APIAI | 13/8/2026 | 14/8/2026 | Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. | |
| Aplazada | Alta (7.5) | 0.36% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept… | |
| Aplazada | Media (6.5) | 0.34% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information. | |
| Aplazada | Crítica (9.1) | 0.42% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free. | |
| Aplazada | Alta (8.1) | 0.38% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. | |
| Aplazada | Media (6.5) | 0.27% | — | Inspireui Mstore APIAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4. | |
| Aplazada | Media (6.5) | 0.46% | — | Inspireui Mstore APIAI | 17/6/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Inspireui Mstore APIAI | 10/5/2026 | 25/7/2026 | WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server. | |
| Aplazada | Media (4.3) | 0.36% | — | Inspireui Mstore APIAI | 9/4/2026 | 24/7/2026 | The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist, blocklist, or validation of meta keys.… | |
| Analizada | Media (4.3) | 0.29% | — | Inspireui Mstore API | 27/5/2025 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Alta (7.3) | 0.34% | — | Inspireui Mstore API | 2/5/2025 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering. This makes it possible for unauthenticated attackers to to register with the… | |
| Analizada | Media (5.4) | 0.33% | — | Inspireui Mstore API | 13/12/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type validation. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.46% | — | Inspireui Mstore API | 20/11/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Analizada | Media (6.5) | 0.38% | — | Inspireui Mstore API | 13/9/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function.… | |
| Analizada | Alta (8.8) | 0.78% | — | Inspireui Mstore API | 13/9/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up to, and including, 4.15.3. This makes it possible for authenticated attackers, with subscriber-level… | |
| Analizada | Alta (8.1) | 0.66% | — | Inspireui Mstore API | 15/8/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in the 'verify_id_token' function. This makes it possible for unauthenticated attackers to log in as any… | |
| Modificada | Crítica (9.8) | 0.67% | — | Inspireui Mstore API | 12/7/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and 'firebase_sms_login_v2' functions. This makes it… | |
| Modificada | Alta (8.8) | 0.22% | — | Inspireui Mstore API | 29/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in InspireUI MStore API.This issue affects MStore API: from n/a through 4.10.1. | |
| Modificada | Crítica (9.8) | 0.55% | — | Inspireui Mstore API | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This issue affects MStore API: from n/a through 4.0.6. | |
| Modificada | Crítica (9.8) | 2.9% | — | Inspireui Mstore API | 3/11/2023 | 17/6/2026 | The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address. | |
| Modificada | Media (4.3) | 0.30% | — | Inspireui Mstore API | 12/7/2023 | 17/6/2026 | The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenticated attackers to update the firebase server key to push notification when order status changed via a forged request… |