CVE-2023-3200: MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Message Update
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstoreupdatenewordermessage function. This makes it possible for unauthenticated attackers to update new order message via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update the MStore API plugin so that the function mstore_update_new_order_message validates a nonce before processing requests (the issue is missing nonce validation, which enables CSRF updates to new order message).
MStore API plugin for WordPress Nonce validation for mstore_update_new_order_message = Enable/require nonce validation
Event History
Frequently Asked Questions
What is CVE-2023-3200?
CVE-2023-3200 is a vulnerability in the MStore API plugin for WordPress that allows unauthenticated attackers to update new order messages via a forged request.
How severe is CVE-2023-3200?
CVE-2023-3200 has a severity value of 4.3, which is considered medium.
What is the affected software for CVE-2023-3200?
The affected software for CVE-2023-3200 is the MStore API plugin for WordPress with a version up to and including 3.9.6.
What is the Common Weakness Enumeration (CWE) for CVE-2023-3200?
The CWE for CVE-2023-3200 is CWE-352.
How can I fix CVE-2023-3200?
To fix CVE-2023-3200, update the MStore API plugin for WordPress to version 3.9.7 or newer.