CVE-2023-3277: MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3277?
CVE-2023-3277 is a vulnerability in the MStore API plugin for WordPress that allows unauthenticated attackers to log in as any user by exploiting the improper implementation of the Apple login feature.
How severe is CVE-2023-3277?
CVE-2023-3277 is considered critical with a severity score of 9.8.
Which version of the MStore API plugin for WordPress is affected by CVE-2023-3277?
Versions up to and including 4.10.7 of the MStore API plugin for WordPress are affected by CVE-2023-3277.
How does CVE-2023-3277 allow unauthorized account access and privilege escalation?
CVE-2023-3277 allows unauthenticated attackers to log in as any user if they know the user's email address.
Are there any references for CVE-2023-3277?
References for CVE-2023-3277 can be found at the following links: [Link 1](https://www.wordfence.com/threat-intel/vulnerabilities/id/1c7c0c35-5f44-488f-9fe1-269ea4a73854?source=cve), [Link 2](https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L821).