CVE-2026-18234: MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment being taken.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including users with the Subscriber role. An attacker does not need administrative or shop-management privileges.
What conditions are required for exploitation?
The affected MStore API wallet payment handling must be available, and the attacker needs an authenticated WordPress account. The issue can be used against arbitrary orders because ownership of the targeted order is not verified.
What is the practical impact of a successful exploit?
An attacker can mark arbitrary orders as paid without a payment being taken. For most payment methods, the wallet balance is not deducted during the payment handling.
What version should be used to remediate the issue?
Upgrade MStore API to version 4.21.1 or later. Versions before 4.21.1 are affected.