CVE-2024-12042: MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting)
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload HTML files with arbitrary web scripts that will execute whenever a user accesses the file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12042?
CVE-2024-12042 is classified as a medium severity vulnerability due to its Stored Cross-Site Scripting risk.
How do I fix CVE-2024-12042?
To fix CVE-2024-12042, update the MStore API plugin to version 4.16.5 or later to address the insufficient file type validation.
Which versions are affected by CVE-2024-12042?
CVE-2024-12042 affects all versions of the MStore API plugin up to and including version 4.16.4.
What kind of vulnerability is CVE-2024-12042?
CVE-2024-12042 is a Stored Cross-Site Scripting vulnerability that can be exploited through profile picture uploads.
Who is impacted by CVE-2024-12042?
Users of the MStore API plugin for WordPress are at risk if they are using versions vulnerable to CVE-2024-12042.