Inspireui
Inspireui Mstore API: vulnerabilidades y CVE
Inspireui Mstore API tiene 40 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses12
Críticas14
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13447 | Crítica (9.8) | 0.45% | — | 5 sept 2026 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the… |
| CVE-2026-18234 | Media (6.5) | 0.17% | — | 29 ago 2026 | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing… |
| CVE-2026-18233 | Media (6.5) | 0.17% | — | 29 ago 2026 | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary… |
| CVE-2026-27543 | Alta (8.1) | 0.37% | — | 13 ago 2026 | Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. |
| CVE-2026-16041 | Alta (7.5) | 0.36% | — | 7 ago 2026 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product… |
| CVE-2026-16039 | Media (6.5) | 0.34% | — | 7 ago 2026 | The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store… |
| CVE-2026-16038 | Crítica (9.1) | 0.42% | — | 7 ago 2026 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to… |
| CVE-2026-16030 | Alta (8.1) | 0.38% | — | 7 ago 2026 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered… |
| CVE-2026-57375 | Media (6.5) | 0.27% | — | 13 jul 2026 | Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4. |
| CVE-2026-54817 | Media (6.5) | 0.46% | — | 17 jun 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4. |
| CVE-2021-47933 | Crítica (9.3) | 0.59% | — | 10 may 2026 | WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP… |
| CVE-2026-3568 | Media (4.3) | 0.36% | — | 9 abr 2026 | The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php… |
| CVE-2025-4683 | Media (4.3) | 0.29% | — | 27 may 2025 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to,… |
| CVE-2025-3438 | Alta (7.3) | 0.34% | — | 2 may 2025 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of… |
| CVE-2024-12042 | Media (5.4) | 0.33% | — | 13 dic 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4… |
| CVE-2024-11179 | Media (6.5) | 0.46% | — | 20 nov 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient… |
| CVE-2024-8269 | Media (6.5) | 0.38% | — | 13 sept 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking… |
| CVE-2024-8242 | Alta (8.8) | 0.78% | — | 13 sept 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up… |
| CVE-2024-7628 | Alta (8.1) | 0.66% | — | 15 ago 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in the… |
| CVE-2024-6328 | Crítica (9.8) | 0.67% | — | 12 jul 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the… |
| CVE-2023-50878 | Alta (8.8) | 0.22% | — | 29 dic 2023 | Cross-Site Request Forgery (CSRF) vulnerability in InspireUI MStore API.This issue affects MStore API: from n/a through 4.10.1. |
| CVE-2023-45055 | Crítica (9.8) | 0.55% | — | 6 nov 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This issue affects MStore API: from n/a through 4.0.6. |
| CVE-2023-3277 | Crítica (9.8) | 2.9% | — | 3 nov 2023 | The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows… |
| CVE-2023-3202 | Media (4.3) | 0.30% | — | 12 jul 2023 | The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenticated attackers to… |
| CVE-2023-3199 | Media (4.3) | 0.30% | — | 12 jul 2023 | The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_title function. This makes it possible for unauthenticated attackers to… |
| CVE-2023-3209 | Baja (3.5) | 0.27% | — | 10 jul 2023 | The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both. |
| CVE-2023-3131 | Media (4.3) | 0.63% | — | 10 jul 2023 | The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both. |
| CVE-2023-3077 | Crítica (9.8) | 5.5% | — | 10 jul 2023 | The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable… |
| CVE-2023-3076 | Crítica (9.8) | 2.2% | — | 10 jul 2023 | The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to… |
| CVE-2023-3197 | Crítica (9.8) | 3.9% | — | 24 jun 2023 | The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.