CVE-2023-3201: MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstoreupdatenewordertitle function. This makes it possible for unauthenticated attackers to update new order title via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3201?
CVE-2023-3201 is a vulnerability in the MStore API plugin for WordPress that allows unauthenticated attackers to update new order titles via a forged request.
How severe is CVE-2023-3201?
CVE-2023-3201 has a severity score of 4.3, which is considered medium.
Which software is affected by CVE-2023-3201?
The MStore API plugin for WordPress version 3.9.6 and earlier is affected by CVE-2023-3201.
How can I fix CVE-2023-3201?
To fix CVE-2023-3201, update the MStore API plugin for WordPress to a version beyond 3.9.6, where the vulnerability has been patched.
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is an attack where an attacker tricks a victim into performing unwanted actions on a web application, often in the victim's context.