Executive brief
The MStore API WordPress plugin contains a flaw in its wallet payment system that allows any registered user to mark other customers' orders as paid without actually paying for them. An attacker with a Subscriber-level account can use a small wallet top-up to complete an unlimited number of arbitrary orders at no cost, enabling payment fraud and order manipulation.
Technical details
The vulnerability is a broken access control flaw (CWE-862) in the wallet payment handling endpoint (/wp-json/api/flutter_tera_wallet/process_payment). The plugin fails to verify that the order being marked as paid belongs to the authenticated requester, and only deducts wallet balance when the target order's own payment method is wallet-based—not for other payment methods. An authenticated attacker can enumerate WooCommerce order IDs (which are sequential integers) and send a POST request with a victim's order ID to mark arbitrary unpaid orders as completed. The vulnerability requires authentication (Subscriber role or above) and a wallet balance equal to at least one target order total, but once established, allows unlimited fraud with no per-order payment deduction. Fixed in version 4.21.1.
Affected products
- MStore API before 4.21.1
Timeline
- 2026-08-27: disclosed
- 2026-08-29: patched: Fixed in version 4.21.1