CVE-2023-3203: MStore API <= 3.9.6 - Cross-Site Request Forgery to Product Limit Update
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstoreupdatelimitproduct function. This makes it possible for unauthenticated attackers to update limit the number of product per category to use cache data in home screen via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3203?
CVE-2023-3203 is a vulnerability in the MStore API plugin for WordPress that allows unauthenticated attackers to update the number of products per category without proper validation.
How severe is CVE-2023-3203?
CVE-2023-3203 has a severity level of 4.3, which is considered medium.
How does CVE-2023-3203 affect the MStore API plugin for WordPress?
CVE-2023-3203 affects the MStore API plugin for WordPress by allowing unauthenticated attackers to manipulate the number of products per category.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2023-3203?
CVE-2023-3203 is associated with CWE-352, which is a vulnerability related to Cross-Site Request Forgery (CSRF).
Are there any references or resources related to CVE-2023-3203?
Yes, you can find more information about CVE-2023-3203 at the following references: [Link 1](https://plugins.trac.wordpress.org/browser/mstore-api/trunk/mstore-api.php#L222), [Link 2](https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2925048%40mstore-api&new=2925048%40mstore-api&sfp_email=&sfph_mail=), [Link 3](https://www.wordfence.com/threat-intel/vulnerabilities/id/1aed51a2-9fd4-43bb-b72d-ae8e51ee6e87?source=cve).