CVE-2026-16038: MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
Published Aug 7, 2026
·Updated
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.
Affected Software
1 affected component
WordPress plugin MStore API<4.21.0
Event History
Aug 7, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-16038?
CVE-2026-16038 has a risk score of 71, indicating a significant potential impact on security.
2
How do I fix CVE-2026-16038?
To fix CVE-2026-16038, update the MStore API WordPress plugin to version 4.21.0 or later.
3
What does CVE-2026-16038 allow an attacker to do?
CVE-2026-16038 allows an unauthenticated attacker to bypass payment verification and mark orders as fully paid.
4
Which WordPress plugin is affected by CVE-2026-16038?
CVE-2026-16038 affects the MStore API WordPress plugin versions prior to 4.21.0.
5
When was CVE-2026-16038 published?
CVE-2026-16038 was published on August 7, 2026.