Impact
The MStore API WordPress plugin fails to verify that an order belongs to the requester when marking it as completed. An authenticated user, even one with a Subscriber role, can arbitrarily declare any order paid and finalized without processing a payment. This flaw enables fraudulent chargebacks, financial loss, and undermines the integrity of the e‑commerce workflow.
Affected Systems
Versions of the MStore API plugin older than 4.21.1 on WordPress sites are affected. No specific vendor field is provided beyond the plugin name, and no detailed version list is available beyond the known upper bound of 4.21.1.
Risk and Exploitability
The vulnerability requires authentication but not privileged access, so any logged‑in user can exploit it. The CVSS score is not supplied, and the EPSS value is unavailable, but the flaw is included in the CISA KEV catalog? No, it is not listed. Despite the lack of a public exploit, the attack surface is large because any Subscriber can use the affected endpoint to trigger payment fraud.
OpenCVE Enrichment