WordPress Plugin Vulnerabilities

MStore API < 4.10.8 - Unauthenticated Privilege Escalation

Description

The plugin does not implement the Apple login feature correctly, which could lead to unauthorized account access and privilege escalation if the attacker knows the user's email address.

Affects Plugins

Fixed in 4.10.8

References

Miscellaneous

Original Researcher
Truoc Phan, An Đặng
Verified
No

Timeline

Publicly Published
2023-06-19 (about 2 years ago)
Added
2023-11-03 (about 2 years ago)
Last Updated
2023-11-08 (about 2 years ago)

Other