Impact
The MStore API WordPress plugin before version 4.21.0 allows any internet user to submit product reviews through a REST endpoint without providing credentials or verifying ownership of the product. The flaw permits the attacker to choose the reviewer name, email address, and star rating, thereby compromising the integrity of the WooCommerce review system. This lack of authorization enables unauthorized modifications to customer feedback, potentially skewing product ratings and damaging the store’s reputation.
Affected Systems
Any WordPress site that has the MStore API plugin installed with a version older than 4.21.0 is affected. No further vendor or product details are noted beyond the specific plugin.
Risk and Exploitability
Because the vulnerability is unauthenticated, no special access is required; any user can craft an HTTP request to create a review. The CVSS score of 7.5 signals a medium‑to‑high risk, while the EPSS score of less than 1% indicates a low to moderate likelihood of exploitation in the wild. The potential for widespread reputational harm to a WooCommerce store raises the overall threat level. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment