Description
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
Published: 2026-08-13
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MStore API plugin for WordPress contains an unauthenticated privilege escalation flaw that allows an attacker to gain higher privileges than intended. The flaw is a classic example of improper authorization (CWE‑266). If exploited, an attacker could perform actions normally restricted to administrators, thereby compromising confidentiality, integrity, and potentially availability of the WordPress site.

Affected Systems

WordPress sites that have the MStore API plugin installed and running a version through 4.20.0. The vulnerability is present in all builds of the plugin up to that version, regardless of the WordPress core version.

Risk and Exploitability

The CVSS score of 8.1 places this flaw in the high‑severity range, indicating a substantial risk if left unmitigated. No EPSS score is available, so the exploitation probability cannot be quantified, but the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote and does not require authentication, meaning any user who can access the site could ascend privileges by interacting with plugin endpoints. The impact remains confined to sites that have the vulnerable plugin installed. The absence of a known exploit makes the risk lower than it could be, yet the high potential impact warrants prompt remediation.

Generated by OpenCVE AI on August 13, 2026 at 15:24 UTC.

Remediation

Vendor Solution

Update the WordPress MStore API plugin to the latest available version (at least 4.21.0).


OpenCVE Recommended Actions

  • Upgrade the MStore API plugin to version 4.21.0 or later, which removes the privilege escalation flaw.
  • If an upgrade is not immediately possible, temporarily disable the plugin on affected WordPress installations until a patch can be applied.
  • Restrict the creation of new high‑privilege accounts and audit existing user roles to minimize the damage that could be caused if an attacker gains elevated privileges.

Generated by OpenCVE AI on August 13, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Fluxbuilder
Fluxbuilder mstore Api
Wordpress
Wordpress wordpress
Vendors & Products Fluxbuilder
Fluxbuilder mstore Api
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
Title WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Fluxbuilder Mstore Api
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:16:56.080Z

Reserved: 2026-02-20T11:18:46.194Z

Link: CVE-2026-27543

cve-icon Vulnrichment

Updated: 2026-08-13T15:16:51.452Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:16:56.763

Modified: 2026-08-13T16:18:01.320

Link: CVE-2026-27543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:00:10Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment