WordPress Plugin Vulnerabilities

MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet

Description

The plugin does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment being taken.

Proof of Concept

Affects Plugins

Fixed in 4.21.1

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-08-27 (about 3 days ago)
Added
2026-08-27 (about 2 days ago)
Last Updated
2026-08-27 (about 2 days ago)

Other