Description
The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.
Published: 2026-10-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized order payment and fulfillment
Action: Patch
AI Analysis

Impact

The MStore API WordPress plugin version 4.21.1 through 4.22.0 contains an authorization flaw that allows any authenticated user with a self‑registerable account to modify the status field of their own unpaid order. By changing the status to paid or fulfilled, an attacker can receive goods without completing the payment process. This flaw represents a classic privilege escalation and financial loss scenario, tied to the CWE-862 weakness of missing authorization.

Affected Systems

Customer sites running the MStore API plugin older than version 4.22.1, specifically those on 4.21.1, 4.21.2, 4.22.0, and any intermediate releases within that range. The vulnerability affects the order management functionality exposed to authenticated users.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of 0.00185 reflects a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need only an authenticated, self‑registered account to trigger the exploitation path; no privileged access or admin rights are required. The flaw can be leveraged by any customer in the system to bypass payment and fulfill orders, resulting in direct revenue loss for the site owner.

Generated by OpenCVE AI on October 2, 2026 at 15:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the MStore API plugin to version 4.22.1 or later, which removes the ability for users to modify the order status field.
  • If an immediate update is not possible, restrict the ability to change order status to administrator or staff accounts by adjusting the plugin’s permission settings or modifying the code to reject status changes from non‑privileged users.
  • Audit and enforce that order status changes can only occur after a successful payment transaction by adding a validation check that requires a completed payment before permitting status updates.

Generated by OpenCVE AI on October 2, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.
Title MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T10:54:09.871Z

Reserved: 2026-09-24T09:16:57.925Z

Link: CVE-2026-97219

cve-icon Vulnrichment

Updated: 2026-10-02T10:44:30.780Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T07:16:39.170

Modified: 2026-10-02T18:00:34.733

Link: CVE-2026-97219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:00:13Z

Weaknesses