MStore API – Create Native Android & iOS Apps On The Cloud
mstore-api · plugin
Known security vulnerabilities for MStore API – Create Native Android & iOS Apps On The Cloud. Find out in seconds which version runs on your site with WP Lens.
28 known vulnerabilities
9 critical · 5 with public exploit code · latest Sep 5, 2026
Vulnerabilities
- Critical 9.8
MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery
- Critical 9.8
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass
- Critical 9.8
WordPress MStore API Plugin <= 4.0.6 is vulnerable to SQL Injection
- Critical 9.8
MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
- Critical 9.8
MStore API <= 4.0.1 - Unauthenticated SQL Injection
- Critical 9.8
MStore API <= 3.9.1 - Authentication Bypass
- Critical 9.8
MStore API <= 3.9.0 - Authentication Bypass
- Critical 9.8
MStore API <= 3.9.2 - Authentication Bypass
- Critical 9.3
WordPress MStore API 2.0.6 Arbitrary File Upload
- High 8.8
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload
- High 8.8
WordPress MStore API Plugin <= 4.10.1 is vulnerable to Cross Site Request Forgery (CSRF)
- High 8.1
WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability
- High 8.1
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover
- High 7.5
WordPress MStore API Plugin <= 3.9.7 is vulnerable to SQL Injection
- High 7.3
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation
- Medium 6.5
WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability
- Medium 6.5
WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability
- Medium 6.5
MStore API <= 4.15.7 - Authenticated (Subscriber+) SQL Injection
- Medium 6.5
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration
- Medium 5.4
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting)
- Medium 4.3
MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update
- Medium 4.3
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation
- Medium 4.3
MStore API <= 3.9.6 - Cross-Site Request Forgery to Firebase Server Key Update
- Medium 4.3
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update
- Medium 4.3
MStore API <= 3.9.6 - Cross-Site Request Forgery to Product Limit Update
- Medium 4.3
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update
- Medium 4.3
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Message Update
- Medium 4.3
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Status Update