CVE-2023-3077: MStore API < 3.9.8 - Unauthenticated Blind SQLi
The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocommerce-appointments plugin.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3077?
CVE-2023-3077 is a vulnerability in the MStore API WordPress plugin before version 3.9.8 that allows unauthenticated users to perform a Blind SQL injection.
How severe is CVE-2023-3077?
CVE-2023-3077 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
Who is affected by CVE-2023-3077?
Organizations using the MStore API WordPress plugin before version 3.9.8 are affected by CVE-2023-3077 if they have elected to pay for access to the plugin's pro features.
How can CVE-2023-3077 be exploited?
CVE-2023-3077 can be exploited by unauthenticated users by injecting malicious SQL statements into a vulnerable parameter of the plugin.
How can I fix CVE-2023-3077?
To fix CVE-2023-3077, update the MStore API WordPress plugin to version 3.9.8 or higher.