WordPress Plugin Vulnerabilities

MStore API – Create Native Android & iOS Apps On The Cloud < 4.17.5 - Unauthenticated Limited Privilege Escalation

Description

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering. This makes it possible for unauthenticated attackers to to register with the 'wcfm_vendor' role, which is a Store Vendor role in the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress. The vulnerability can only be exploited if the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin is installed and activated. The vulnerability was partially patched in version 4.17.3.

Affects Plugins

Fixed in 4.17.5

References

Classification

Miscellaneous

Original Researcher
Brian Sans-Souci (liardom)
Verified
No

Timeline

Publicly Published
2025-05-01 (about 1 year ago)
Added
2025-05-01 (about 1 year ago)
Last Updated
2025-05-02 (about 1 year ago)

Other