Executive brief
The MStore API plugin for WordPress, which connects mobile applications to e-commerce stores, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to perform actions or access data that should be restricted to administrators or authenticated users. If exploited, this could lead to unauthorized changes to store settings or the exposure of sensitive information, potentially impacting business operations and customer trust.
Technical details
A missing authorization vulnerability (CWE-862) exists in the FluxBuilder MStore API (mstore-api) plugin for WordPress. The flaw is rooted in incorrectly configured access control security levels within the API component. An unauthenticated remote attacker can exploit this by sending crafted requests to the API, allowing them to execute functions or access data that should require higher privilege levels. The vulnerability affects all versions up to and including 4.18.4; it was addressed in version 4.19.0.
Affected products
- FluxBuilder MStore API <= 4.18.4
Timeline
- 2026-04-21: other: Vulnerability reported by researcher HaiND
- 2026-07-07: patched: Patch released in version 4.19.0
- 2026-07-13: advisory: CVE published to NVD