WordPress Plugin Vulnerabilities
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
Description
The plugin does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Sai Praneeth Koti
Submitter
Sai Praneeth Koti
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-03 (about 25 days ago)
Added
2026-08-03 (about 25 days ago)
Last Updated
2026-08-03 (about 25 days ago)