CVE-2023-3076: MStore API < 3.9.9 - Unauthenticated Privilege Escalation
The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3076?
CVE-2023-3076 is a vulnerability in the MStore API WordPress plugin before version 3.9.9 that allows visitors to create user accounts with the role of their choice.
How does CVE-2023-3076 impact websites?
CVE-2023-3076 allows unauthorized visitors to create user accounts on affected websites, which can lead to potential misuse of user privileges.
Which version of the MStore API plugin is affected by CVE-2023-3076?
The MStore API WordPress plugin versions up to, but excluding, version 3.9.9 are affected by CVE-2023-3076.
What is the severity of CVE-2023-3076?
CVE-2023-3076 has a severity level of critical with a value of 9.
How can I fix CVE-2023-3076?
To fix CVE-2023-3076, it is recommended to update the MStore API WordPress plugin to version 3.9.9 or higher.