WordPress Plugin Vulnerabilities
MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter
Description
The plugin does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
cyberkareem
Submitter
cyberkareem
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-30 (about 2 days ago)
Added
2026-09-30 (about 1 day ago)
Last Updated
2026-09-30 (about 1 day ago)