Impact
The MStore API plugin for WordPress contains an unauthenticated privilege escalation flaw that allows an attacker to gain higher privileges than intended. The flaw is a classic example of improper authorization (CWE‑266). If exploited, an attacker could perform actions normally restricted to administrators, thereby compromising confidentiality, integrity, and potentially availability of the WordPress site.
Affected Systems
WordPress sites that have the MStore API plugin installed and running a version through 4.20.0. The vulnerability is present in all builds of the plugin up to that version, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 8.1 places this flaw in the high‑severity range, indicating a substantial risk if left unmitigated. No EPSS score is available, so the exploitation probability cannot be quantified, but the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote and does not require authentication, meaning any user who can access the site could ascend privileges by interacting with plugin endpoints. The impact remains confined to sites that have the vulnerable plugin installed. The absence of a known exploit makes the risk lower than it could be, yet the high potential impact warrants prompt remediation.
OpenCVE Enrichment