Impact
The MStore API WordPress plugin version 4.21.1 through 4.22.0 contains an authorization flaw that allows any authenticated user with a self‑registerable account to modify the status field of their own unpaid order. By changing the status to paid or fulfilled, an attacker can receive goods without completing the payment process. This flaw represents a classic privilege escalation and financial loss scenario, tied to the CWE-862 weakness of missing authorization.
Affected Systems
Customer sites running the MStore API plugin older than version 4.22.1, specifically those on 4.21.1, 4.21.2, 4.22.0, and any intermediate releases within that range. The vulnerability affects the order management functionality exposed to authenticated users.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of 0.00185 reflects a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need only an authenticated, self‑registered account to trigger the exploitation path; no privileged access or admin rights are required. The flaw can be leveraged by any customer in the system to bypass payment and fulfill orders, resulting in direct revenue loss for the site owner.
OpenCVE Enrichment