MStore API – Create Native Android & iOS Apps On The Cloud

27 known CVEs 3K+ active installs

Scan My Site Free

UNKNOWN: 27
Known Vulnerabilities 27
CVE-2026-3568 UNKNOWN EPSS 0.1%
Published 2026-04-09 · Affected: *
The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/fl
CVE-2024-6328 UNKNOWN EPSS 0.5%
Published 2024-07-12 · Affected: *
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient ver
CVE-2024-6328 UNKNOWN EPSS 0.5%
Published 2024-07-12 · Affected: *
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient ver
CVE-2023-3277 UNKNOWN EPSS 0.9%
Published 2023-11-03 · Affected: *
The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login fea
CVE-2023-3277 UNKNOWN EPSS 0.9%
Published 2023-11-03 · Affected: *
The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login fea
CVE-2023-3202 UNKNOWN EPSS 0.2%
Published 2023-07-12 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenti
CVE-2023-3202 UNKNOWN EPSS 0.2%
Published 2023-07-12 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenti
CVE-2023-3199 UNKNOWN EPSS 0.2%
Published 2023-07-12 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_title function. This makes it possible for unauthentic
CVE-2023-3199 UNKNOWN EPSS 0.2%
Published 2023-07-12 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_title function. This makes it possible for unauthentic
CVE-2023-3197 UNKNOWN EPSS 0.9%
Published 2023-06-24 · Affected: *
The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplie
CVE-2023-3197 UNKNOWN EPSS 0.9%
Published 2023-06-24 · Affected: *
The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplie
CVE-2023-3203 UNKNOWN EPSS 0.2%
Published 2023-06-14 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_limit_product function. This makes it possible for unauthenticated
CVE-2023-3203 UNKNOWN EPSS 0.2%
Published 2023-06-14 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_limit_product function. This makes it possible for unauthenticated
CVE-2023-3201 UNKNOWN EPSS 0.2%
Published 2023-06-14 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticate
CVE-2023-3201 UNKNOWN EPSS 0.2%
Published 2023-06-14 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticate
CVE-2023-3200 UNKNOWN EPSS 0.2%
Published 2023-06-14 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_message function. This makes it possible for unauthentica
CVE-2023-3200 UNKNOWN EPSS 0.2%
Published 2023-06-14 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_message function. This makes it possible for unauthentica
CVE-2023-3198 UNKNOWN EPSS 0.2%
Published 2023-06-14 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_message function. This makes it possible for unauthent
CVE-2023-3198 UNKNOWN EPSS 0.2%
Published 2023-06-14 · Affected: *
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_message function. This makes it possible for unauthent
CVE-2020-36713 UNKNOWN EPSS 0.7%
Published 2023-06-07 · Affected: *
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' route
CVE-2020-36713 UNKNOWN EPSS 0.7%
Published 2023-06-07 · Affected: *
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' route
CVE-2023-2734 UNKNOWN EPSS 0.9%
Published 2023-05-25 · Affected: *
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart
CVE-2023-2734 UNKNOWN EPSS 0.9%
Published 2023-05-25 · Affected: *
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart
CVE-2023-2733 UNKNOWN EPSS 0.7%
Published 2023-05-25 · Affected: *
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupo
CVE-2023-2733 UNKNOWN EPSS 0.7%
Published 2023-05-25 · Affected: *
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupo
CVE-2023-2732 UNKNOWN EPSS 1.0%
Published 2023-05-25 · Affected: *
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add l
CVE-2023-2732 UNKNOWN EPSS 1.0%
Published 2023-05-25 · Affected: *
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add l

Is MStore API – Create Native Android & iOS Apps On The Cloud running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free