MStore API < 3.9.7 - Subscriber+ Unauthorized Settings Update
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.
Affected products
Unknown · MStore API