Skip to content
Noroxi

MStore API – Create Native Android & iOS Apps On The Cloud

mstore-api · plugin

Known security vulnerabilities for MStore API – Create Native Android & iOS Apps On The Cloud. Find out in seconds which version runs on your site with WP Lens.

28 known vulnerabilities

9 critical · 5 with public exploit code · latest Sep 5, 2026

Vulnerabilities

  • CVE-2026-13447

    MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery

    Critical 9.8
  • CVE-2024-6328

    MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass

    Critical 9.8
  • CVE-2023-45055

    WordPress MStore API Plugin <= 4.0.6 is vulnerable to SQL Injection

    Critical 9.8
  • CVE-2023-3277

    MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation

    Critical 9.8
  • CVE-2023-3197

    MStore API <= 4.0.1 - Unauthenticated SQL Injection

    Critical 9.8
  • CVE-2023-2734

    MStore API <= 3.9.1 - Authentication Bypass

    Critical 9.8
  • CVE-2023-2733

    MStore API <= 3.9.0 - Authentication Bypass

    Critical 9.8
  • CVE-2023-2732

    MStore API <= 3.9.2 - Authentication Bypass

    Critical 9.8
  • CVE-2021-47933

    WordPress MStore API 2.0.6 Arbitrary File Upload

    Critical 9.3
  • CVE-2024-8242

    MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload

    High 8.8
  • CVE-2023-50878

    WordPress MStore API Plugin <= 4.10.1 is vulnerable to Cross Site Request Forgery (CSRF)

    High 8.8
  • CVE-2026-27543

    WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability

    High 8.1
  • CVE-2024-7628

    MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover

    High 8.1
  • CVE-2022-47614

    WordPress MStore API Plugin <= 3.9.7 is vulnerable to SQL Injection

    High 7.5
  • CVE-2025-3438

    MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation

    High 7.3
  • CVE-2026-57375

    WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2026-54817

    WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability

    Medium 6.5
  • CVE-2024-11179

    MStore API <= 4.15.7 - Authenticated (Subscriber+) SQL Injection

    Medium 6.5
  • CVE-2024-8269

    MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration

    Medium 6.5
  • CVE-2024-12042

    MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting)

    Medium 5.4
  • CVE-2026-3568

    MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update

    Medium 4.3
  • CVE-2025-4683

    MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation

    Medium 4.3
  • CVE-2023-3202

    MStore API <= 3.9.6 - Cross-Site Request Forgery to Firebase Server Key Update

    Medium 4.3
  • CVE-2023-3199

    MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update

    Medium 4.3
  • CVE-2023-3203

    MStore API <= 3.9.6 - Cross-Site Request Forgery to Product Limit Update

    Medium 4.3
  • CVE-2023-3201

    MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update

    Medium 4.3
  • CVE-2023-3200

    MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Message Update

    Medium 4.3
  • CVE-2023-3198

    MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Status Update

    Medium 4.3

← Back to directory