CVE-2023-3131: MStore API < 3.9.7 - Subscriber+ Unauthorized Settings Update
The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/MStore APIto a version that resolves this vulnerability.Fixed in 3.9.7
Event History
Frequently Asked Questions
What is CVE-2023-3131?
CVE-2023-3131 is a vulnerability in the MStore API WordPress plugin before version 3.9.7 that allows unauthorized access to certain functions.
How severe is CVE-2023-3131?
CVE-2023-3131 has a severity score of 4.3 (medium).
What software is affected by CVE-2023-3131?
The Inspireui Mstore Api WordPress plugin version up to 3.9.7 is affected by CVE-2023-3131.
What are the security risks of CVE-2023-3131?
CVE-2023-3131 exposes the MStore API WordPress plugin to unauthorized access and potential abuse of certain functions.
How do I fix CVE-2023-3131?
To fix CVE-2023-3131, update the MStore API WordPress plugin to version 3.9.7 or newer.