CVE Database
/

CVE-2023-3076

Back to search

CVE-2023-3076

Published: Jul 10, 2023

Modified: Nov 12, 2024

PUBLISHED

Description

The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.

VendorProductVersions

Unknown

MStore API

affected
0 - < 3.9.9

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now