CVE-2020-36713: MStore API <= 2.1.5 - Authentication Bypass
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'updateuserprofile' routes. This makes it possible for unauthenticated attackers to create new administrator accounts, delete existing administrator accounts, or escalate privileges on any account.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the MStore API plugin for WordPress?
The vulnerability ID is CVE-2020-36713.
What is the severity of CVE-2020-36713?
The severity of CVE-2020-36713 is critical with a severity value of 9.8.
What is the cause of CVE-2020-36713?
The cause of CVE-2020-36713 is unrestricted access to the 'register' and 'update_user_profile' routes in the MStore API plugin for WordPress.
How can an attacker exploit CVE-2020-36713?
An attacker can exploit CVE-2020-36713 by creating new administrator accounts or deleting existing administrator accounts on the affected WordPress site.
Is there a fix for CVE-2020-36713?
Yes, the vulnerability has been fixed in version 2.1.6 of the MStore API plugin for WordPress.