Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MStore API — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in MStore API, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities associated with MStore API, a web service interface for the MStore e-commerce platform, focusing on specific software weakness categories. It collects reported defects spanning the product's operational history, covering both legacy and current releases. Readers can track vendor-issued advisories, analyze the prevalence of particular vulnerability classes, and review the complete vulnerability history for this product to identify recurring patterns and assess overall security posture.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-97219 MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter 4.3 Medium 2026-10-02
CVE-2026-18234 MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet - - 2026-08-29
CVE-2026-18233 MStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion - - 2026-08-29
CVE-2026-27543 WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability CWE-266 8.1 High 2026-08-13
CVE-2026-16041 MStore API < 4.21.0 - Unauthenticated Product Review Creation - - 2026-08-07
CVE-2026-16030 MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication - - 2026-08-07
CVE-2026-16039 MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR - - 2026-08-07
CVE-2026-16038 MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways - - 2026-08-07
CVE-2026-57375 WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-07-13
CVE-2026-54817 WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability CWE-288 6.5 Medium 2026-06-17
CVE-2021-47933 WordPress MStore API 2.0.6 Arbitrary File Upload CWE-306 9.8 Critical 2026-05-10
CVE-2023-50878 WordPress MStore API Plugin <= 4.10.1 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 5.4 Medium 2023-12-29
CVE-2023-45055 WordPress MStore API Plugin <= 4.0.6 is vulnerable to SQL Injection CWE-89 8.5 High 2023-11-06
CVE-2023-3131 MStore API < 3.9.7 - Subscriber+ Unauthorized Settings Update 9.1 - 2023-07-10
CVE-2023-3209 MStore API < 3.9.7 - Settings Update via CSRF 9.1 - 2023-07-10
CVE-2023-3077 MStore API < 3.9.8 - Unauthenticated Blind SQLi 9.8 - 2023-07-10
CVE-2023-3076 MStore API < 3.9.9 - Unauthenticated Privilege Escalation 8.1 - 2023-07-10
CVE-2022-47614 WordPress MStore API Plugin <= 3.9.7 is vulnerable to SQL Injection CWE-89 7.5 High 2023-06-23
CVE-2021-24148 MStore API < 3.2.0 - Authentication Bypass With Sign In With Apple CWE-287 7.5 - 2021-03-18

All 19 known CVE vulnerabilities affecting MStore API with full Chinese analysis, references, and POCs where available.