CVE-2023-3198: MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Status Update
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstoreupdatestatusordermessage function. This makes it possible for unauthenticated attackers to update status order message via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3198?
CVE-2023-3198 is a vulnerability in the MStore API plugin for WordPress that allows unauthenticated attackers to update status order messages via a forged request.
How severe is CVE-2023-3198?
CVE-2023-3198 has a severity rating of medium with a value of 4.3.
How does CVE-2023-3198 impact the MStore API plugin?
CVE-2023-3198 affects the MStore API plugin by enabling unauthenticated attackers to manipulate status order messages through CSRF attacks.
Which version of the MStore API plugin for WordPress is affected by CVE-2023-3198?
The MStore API plugin version 3.9.6 and prior are affected by CVE-2023-3198.
Is there a fix for CVE-2023-3198?
Yes, updating the MStore API plugin to a version beyond 3.9.6 fixes CVE-2023-3198.