← Back to browse · API

CVE-2023-3277

Severity
CRITICAL
CVSS
9.8
EPSS
0.02888
Risk score
40.21
CISA KEV
No
PoC
No
Published
2023-11-03
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2023-43952, GHSA-7PC7-CRJ3-6P7V
Products
InspireUI:MStore API – Create Native Android & iOS Apps On The Cloud 0 ≤4.10.7
Sources
euvd EUVD-2023-43952

Description

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address.

References