WordPress Plugin Vulnerabilities

MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways

Description

The plugin does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.

Proof of Concept

Affects Plugins

Fixed in 4.21.0

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Sai Praneeth Koti
Submitter
Sai Praneeth Koti
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 25 days ago)
Added
2026-08-03 (about 25 days ago)
Last Updated
2026-08-03 (about 25 days ago)

Other