Lucene search

K
wpvulndbWpvulndbWPVDB-ID:EE425ADC-DA34-4A56-A801-FA4A33E96D14
HistoryJun 13, 2023 - 12:00 a.m.

MStore API < 3.9.7 - Multiple CSRF

2023-06-1300:00:00
wpscan.com
6
mstore api
csrf
vulnerability
order status update
order title update
product limit update
order message update
firebase server key update
security

0.001 Low

EPSS

Percentile

49.8%

The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as Order Status Update, Order Title Update, Product Limit Update, Order Message Update, and Firebase Server Key Update.

CPENameOperatorVersion
mstore-apilt4.0.2

0.001 Low

EPSS

Percentile

49.8%

Related for WPVDB-ID:EE425ADC-DA34-4A56-A801-FA4A33E96D14