Description
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.
Published: 2026-08-07
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MStore API WordPress plugin before version 4.21.0 allows any internet user to submit product reviews through a REST endpoint without providing credentials or verifying ownership of the product. The flaw permits the attacker to choose the reviewer name, email address, and star rating, thereby compromising the integrity of the WooCommerce review system. This lack of authorization enables unauthorized modifications to customer feedback, potentially skewing product ratings and damaging the store’s reputation.

Affected Systems

Any WordPress site that has the MStore API plugin installed with a version older than 4.21.0 is affected. No further vendor or product details are noted beyond the specific plugin.

Risk and Exploitability

Because the vulnerability is unauthenticated, no special access is required; any user can craft an HTTP request to create a review. The CVSS score of 7.5 signals a medium‑to‑high risk, while the EPSS score of less than 1% indicates a low to moderate likelihood of exploitation in the wild. The potential for widespread reputational harm to a WooCommerce store raises the overall threat level. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 8, 2026 at 12:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MStore API plugin to version 4.21.0 or later
  • Disable the product review REST endpoint in the plugin settings or block unauthenticated requests with a web‑application firewall
  • Enforce server‑side access control on the REST route so only authenticated and verified users can submit reviews

Generated by OpenCVE AI on August 8, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Mstore
Mstore mstore Api
Wordpress
Wordpress wordpress
Vendors & Products Mstore
Mstore mstore Api
Wordpress
Wordpress wordpress

Sat, 08 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.
Title MStore API < 4.21.0 - Unauthenticated Product Review Creation
References

Subscriptions

Mstore Mstore Api
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T18:13:51.411Z

Reserved: 2026-07-17T09:21:01.355Z

Link: CVE-2026-16041

cve-icon Vulnrichment

Updated: 2026-08-07T18:13:47.354Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T06:16:56.167

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-16041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:27Z

Weaknesses