CVE-2026-16041: MStore API < 4.21.0 - Unauthenticated Product Review Creation
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MStore API WordPress pluginto a version that resolves this vulnerability.Fixed in 4.21.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16041?
CVE-2026-16041 has a risk score of 52, indicating a moderate level of severity.
How do I fix CVE-2026-16041?
To fix CVE-2026-16041, update the MStore API plugin to version 4.21.0 or later.
What does CVE-2026-16041 allow an attacker to do?
CVE-2026-16041 allows an unauthenticated attacker to create unauthorized product reviews on WooCommerce stores.
What versions of the MStore API plugin are affected by CVE-2026-16041?
CVE-2026-16041 affects all versions of the MStore API plugin prior to 4.21.0.
Is authentication required to exploit CVE-2026-16041?
No, CVE-2026-16041 can be exploited by an unauthenticated attacker.