Executive brief
The FluxBuilder MStore API plugin for WordPress, which is used to connect mobile apps to e-commerce stores, contains a security flaw in its authentication process. An unauthorized attacker can bypass security checks during the password recovery process, potentially allowing them to gain unauthorized access to user accounts. This could lead to the compromise of customer data or administrative control over the website.
Technical details
An authentication bypass vulnerability (CWE-288) exists in the FluxBuilder MStore API plugin for WordPress through version 4.18.4. The flaw resides in the password recovery mechanism, where the application fails to properly validate authentication through the intended primary channel, allowing an alternate path to be exploited. A remote, unauthenticated attacker can leverage this to bypass security controls and potentially gain access to higher-privileged accounts. The issue is addressed in version 4.19.0.
Affected products
- FluxBuilder MStore API up to 4.18.4
Timeline
- 2026-04-14: other: Vulnerability reported by researcher Jakub Herman
- 2026-06-17: advisory: Advisory published by Patchstack and NVD record created
- 2026-06-17: patched: Patch released in version 4.19.0