CVE-2025-4683: MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the createblog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new posts.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4683?
The severity of CVE-2025-4683 is classified as high due to its potential for unauthorized data modification.
How do I fix CVE-2025-4683?
To fix CVE-2025-4683, update the MStore API plugin to version 4.17.6 or later, where the vulnerability has been addressed.
Who is affected by CVE-2025-4683?
Any WordPress installations utilizing the MStore API plugin versions up to and including 4.17.5 are vulnerable to CVE-2025-4683.
What function is vulnerable in CVE-2025-4683?
The create_blog function is the specific vulnerable function in CVE-2025-4683 due to missing capability checks.
What type of attack can exploit CVE-2025-4683?
CVE-2025-4683 can be exploited through unauthorized modifications by authenticated users without proper capabilities.