Extension WordPress
Vulnérabilités MStore API – Create Native Android & iOS Apps On The Cloud
Cette page rassemble les failles publiées pour MStore API – Create Native Android & iOS Apps On The Cloud, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MStore API – Create Native Android & iOS Apps On The Cloud
31 fiches
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 – Missing Authorization
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.18.4. This…
*-4.18.4
4.19.0
07/07/2026
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 – Missing Authorization
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.18.4.…
*-4.18.4
4.19.0
17/06/2026
MStore API <= 4.18.3 – Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update
The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist,…
*-4.18.3
4.18.4
08/04/2026
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 – Missing Authorization to Authenticated (Subscriber+) Posts Creation
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to,…
*-4.17.5
4.17.6
26/05/2025
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 – Unauthenticated Limited Privilege Escalation
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction…
*-4.17.4
4.17.5
01/05/2025
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 – Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting)
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to…
*-4.16.4
4.16.5
12/12/2024
MStore API <= 4.15.7 – Authenticated (Subscriber+) SQL Injection
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on…
*-4.15.7
4.15.8
19/11/2024
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 – Authenticated (Subscriber+) Limited Arbitrary File Upload
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up to, and…
*-4.15.3
4.15.4
12/09/2024
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 – Unauthorized User Registration
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking…
*-4.15.3
4.15.4
12/09/2024
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 – Authentication Bypass to Account Takeover
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in…
*-4.15.2
4.15.3
14/08/2024
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 – Authentication Bypass
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone'…
*-4.14.7
4.15.0
11/07/2024
MStore API <= 4.10.1 – Cross-Site Request Forgery
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 4.10.2 (exclusive). This is due to missing or incorrect nonce validation in the templates/admin/mstore-api-admin-dashboard.php file. This makes it possible for unauthenticated…
*-4.10.1
4.10.2
26/12/2023
MStore API <= 4.0.6 – Authenticated (Subscriber+) SQL Injection
The MStore API plugin for WordPress is vulnerable to SQL Injection via the $name and $search variables in versions up to, and including, 4.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-4.0.6
4.0.7
03/10/2023
MStore API <= 4.0.1 – Unauthenticated SQL Injection
The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation…
*-4.0.1
4.0.2
23/06/2023
MStore API <= 3.9.7 – Unauthenticated SQL Injection
The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'product_id' parameter in versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation…
*-3.9.7
3.9.8
19/06/2023
MStore API <= 3.9.8 – Unauthenticated Privilege Escalation
The MStore API plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.9.8 due to insufficient restriction on roles supplied during registration through the /register REST route. This allows unauthenticated attackers register as…
*-3.9.8
3.9.9
19/06/2023
MStore API <= 3.9.7 – Unauthenticated SQL Injection
The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'store_id' parameter in versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation…
*-3.9.7
3.9.8
19/06/2023
MStore API <= 4.10.7 – Unauthorized Account Access and Privilege Escalation
The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in…
*-4.10.7
4.10.8
19/06/2023
MStore API <= 3.9.6 – Cross-Site Request Forgery to Firebase Server Key Update
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenticated attackers to update the firebase server key to push notification when…
*-3.9.6
3.9.7
13/06/2023
MStore API <= 3.9.6 – Cross-Site Request Forgery to Order Title Update
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticated attackers to update new order title via a forged request granted…
*-3.9.6
3.9.7
13/06/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.