Extension WordPress

Vulnérabilités MStore API – Create Native Android & iOS Apps On The Cloud

Cette page rassemble les failles publiées pour MStore API – Create Native Android & iOS Apps On The Cloud, leurs plages de versions affectées et les correctifs signalés dans la base locale.

31Vulnérabilités
12Critiques
31Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de MStore API – Create Native Android & iOS Apps On The Cloud

31 fiches

CVE-2026-57375 Moyenne · 5,3
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 – Missing Authorization

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.18.4. This…

Versions affectées

*-4.18.4

Correctif

4.19.0

Publication

07/07/2026

CVE-2026-54817 Moyenne · 5,3
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 – Missing Authorization

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.18.4.…

Versions affectées

*-4.18.4

Correctif

4.19.0

Publication

17/06/2026

CVE-2026-3568 Moyenne · 4,3
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API <= 4.18.3 – Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update

The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist,…

Versions affectées

*-4.18.3

Correctif

4.18.4

Publication

08/04/2026

CVE-2025-4683 Moyenne · 4,3
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 – Missing Authorization to Authenticated (Subscriber+) Posts Creation

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to,…

Versions affectées

*-4.17.5

Correctif

4.17.6

Publication

26/05/2025

CVE-2025-3438 Moyenne · 6,5
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 – Unauthenticated Limited Privilege Escalation

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction…

Versions affectées

*-4.17.4

Correctif

4.17.5

Publication

01/05/2025

CVE-2024-12042 Moyenne · 5,4
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 – Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting)

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to…

Versions affectées

*-4.16.4

Correctif

4.16.5

Publication

12/12/2024

CVE-2024-8242 Moyenne · 4,3
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 – Authenticated (Subscriber+) Limited Arbitrary File Upload

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up to, and…

Versions affectées

*-4.15.3

Correctif

4.15.4

Publication

12/09/2024

CVE-2024-8269 Élevée · 7,3
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 – Unauthorized User Registration

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking…

Versions affectées

*-4.15.3

Correctif

4.15.4

Publication

12/09/2024

CVE-2024-7628 Élevée · 8,1
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 – Authentication Bypass to Account Takeover

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in…

Versions affectées

*-4.15.2

Correctif

4.15.3

Publication

14/08/2024

CVE-2024-6328 Critique · 9,8
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 – Authentication Bypass

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone'…

Versions affectées

*-4.14.7

Correctif

4.15.0

Publication

11/07/2024

CVE-2023-50878 Moyenne · 4,3
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API <= 4.10.1 – Cross-Site Request Forgery

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 4.10.2 (exclusive). This is due to missing or incorrect nonce validation in the templates/admin/mstore-api-admin-dashboard.php file. This makes it possible for unauthenticated…

Versions affectées

*-4.10.1

Correctif

4.10.2

Publication

26/12/2023

CVE-2023-3076 Critique · 9,8
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API <= 3.9.8 – Unauthenticated Privilege Escalation

The MStore API plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.9.8 due to insufficient restriction on roles supplied during registration through the /register REST route. This allows unauthenticated attackers register as…

Versions affectées

*-3.9.8

Correctif

3.9.9

Publication

19/06/2023

CVE-2023-3277 Critique · 9,8
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API <= 4.10.7 – Unauthorized Account Access and Privilege Escalation

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in…

Versions affectées

*-4.10.7

Correctif

4.10.8

Publication

19/06/2023

CVE-2023-3202 Moyenne · 4,3
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API <= 3.9.6 – Cross-Site Request Forgery to Firebase Server Key Update

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenticated attackers to update the firebase server key to push notification when…

Versions affectées

*-3.9.6

Correctif

3.9.7

Publication

13/06/2023

CVE-2023-3201 Moyenne · 4,3
MStore API – Create Native Android & iOS Apps On The Cloud

MStore API <= 3.9.6 – Cross-Site Request Forgery to Order Title Update

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticated attackers to update new order title via a forged request granted…

Versions affectées

*-3.9.6

Correctif

3.9.7

Publication

13/06/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités