CVE-2021-24148: MStore API < 3.2.0 - Authentication Bypass With Sign In With Apple
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24148?
CVE-2021-24148 is a business logic issue in the MStore API WordPress plugin versions before 3.2.0 that allows unauthenticated users to recover an authentication cookie with only an email address.
What is the severity of CVE-2021-24148?
The severity of CVE-2021-24148 is classified as critical with a severity value of 9.8.
How can an attacker exploit CVE-2021-24148?
An attacker can exploit CVE-2021-24148 by bypassing authentication with Sign In With Apple and recovering an authentication cookie using only an email address.
How can I fix CVE-2021-24148?
To fix CVE-2021-24148, update the MStore API WordPress plugin to version 3.2.0 or later.
Is there a reference for CVE-2021-24148?
Yes, you can find more information about CVE-2021-24148 at this reference: https://wpscan.com/vulnerability/bf5ddc43-974d-41fa-8276-c1a27d3cc882