CVE-2023-3199: MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstoreupdatestatusordertitle function. This makes it possible for unauthenticated attackers to update status order title via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3199?
CVE-2023-3199 is a vulnerability in the MStore API plugin for WordPress that allows unauthenticated attackers to update status order title.
How severe is CVE-2023-3199?
CVE-2023-3199 has a severity rating of medium.
How does CVE-2023-3199 work?
CVE-2023-3199 works by exploiting the missing nonce validation on the mstore_update_status_order_title function in the MStore API plugin for WordPress.
Which version of the MStore API plugin for WordPress is affected by CVE-2023-3199?
Versions up to and including 3.9.6 of the MStore API plugin for WordPress are affected by CVE-2023-3199.
Is there a fix for CVE-2023-3199?
Currently, there is no known fix for CVE-2023-3199. It is recommended to remove or disable the vulnerable plugin.