WordPress.Plugin.MStoreAPI.add_listing.Authentication.Bypass

description-logoDescription

This indicates an attack attempt to exploit an Authentication Bypass vulnerability in WordPress MStore API Plugin.
The vulnerability is due to lack of authentication on REST-API endpoints created by the plugin. A remote unauthenticated attacker could exploit this vulnerability by sending an HTTP request to the target server. Successfully exploiting these vulnerabilities could allow an attacker to log in as an authenticated user.

affected-products-logoAffected Products

WordPress MStore API Plugin <= 3.9.2

Impact logoImpact

Security Bypass: Remote attackers can bypass security features of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor
https://wordpress.org/plugins/mstore-api/

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2023-08-23 25.626
Modified
Default_action:pass:drop
2023-07-26 25.609
New