Impact
The MStore API WordPress plugin, versions prior to 4.21.1, contains a logic flaw in its wallet payment handling. The plugin does not verify that the order being marked as paid belongs to the authenticated requester and fails to deduct the wallet balance for most payment methods. Consequently, an authenticated user, even a subscriber with minimal privileges, can claim any order as paid without any payment being processed. This flaw represents an improper access control weakness that can lead to unauthorized financial transactions.
Affected Systems
Any WordPress site that installs MStore API before version 4.21.1 is at risk. The vendor of the plugin is not publicly listed, so site administrators must inventory the plugin version used. The problem exists in all instances where the deprecated wallet payment path is enabled, regardless of installation location within the WordPress ecosystem.
Risk and Exploitability
The vulnerability has a high potential impact, as attackers can convert unpaid orders into paid ones, potentially generating revenue for the attacker or causing financial loss for the merchant. The EPSS score is not available, and the vulnerability is not currently listed in CISA's KEV catalog, but the lack of an order ownership check and wallet deduction makes the attack straightforward for any authenticated user. An attacker only needs to have a valid subscriber account and access the plugin’s wallet payment endpoint to trigger the bypass.
OpenCVE Enrichment