WordPress.Plugin.MStoreAPI.add_listing.Authentication.Bypass
Description
This indicates an attack attempt to exploit an Authentication Bypass vulnerability in WordPress MStore API Plugin.
The vulnerability is due to lack of authentication on REST-API endpoints created by the plugin. A remote unauthenticated attacker could exploit this vulnerability by sending an HTTP request to the target server. Successfully exploiting these vulnerabilities could allow an attacker to log in as an authenticated user.
Affected Products
WordPress MStore API Plugin <= 3.9.2
Impact
Security Bypass: Remote attackers can bypass security features of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor
https://wordpress.org/plugins/mstore-api/
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |