WordPress Plugin Vulnerabilities

MStore API < 3.2.0 - Authentication Bypass With Sign In With Apple

Description

The plugin had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

Proof of Concept

Affects Plugins

Fixed in 3.2.0

References

Classification

Miscellaneous

Original Researcher
Vincent Datrier
Submitter
Vincent Datrier
Verified
Yes

Timeline

Publicly Published
2021-02-02 (about 4 years ago)
Added
2021-02-02 (about 4 years ago)
Last Updated
2021-02-18 (about 4 years ago)

Other