CVE-2023-3209: MStore API < 3.9.7 - Settings Update via CSRF
The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/MStore APIto a version that resolves this vulnerability.Fixed in 3.9.7
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3209?
The severity of CVE-2023-3209 is low with a severity value of 3.5.
What is the affected software for CVE-2023-3209?
The affected software for CVE-2023-3209 is the MStore API WordPress plugin before version 3.9.7 by Inspireui.
How does CVE-2023-3209 impact WordPress?
CVE-2023-3209 is a vulnerability in the MStore API WordPress plugin before version 3.9.7 that does not secure most of its AJAX actions, which can lead to potential security threats.
Is there a fix available for CVE-2023-3209?
Yes, the fix for CVE-2023-3209 is to update the MStore API WordPress plugin to version 3.9.7 or later.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-3209?
The Common Weakness Enumeration (CWE) ID for CVE-2023-3209 is CWE-352.