← Back to browse · API

CVE-2023-2732

Severity
CRITICAL
CVSS
9.8
EPSS
0.67511
Risk score
62.83
CISA KEV
No
PoC
No
Published
2023-05-25
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2023-34193, GHSA-Q639-QHHX-5J5J
Products
InspireUI:MStore API – Create Native Android & iOS Apps On The Cloud 0 ≤3.9.2
Sources
euvd EUVD-2023-34193

Description

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

References