Back to search
CVE-2025-11127
Published: Nov 21, 2025
Modified: Nov 21, 2025
PUBLISHED
Description
The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Mstoreapp Mobile App | affected 0 - <= 2.0.8 |
Unknown | Mstoreapp Mobile Multivendor | affected 0 - <= 9.0.1 |
References
https://wpscan.com/vulnerability/6432bd1a-6e44-4a3f-890b-df2bd877d626/
exploit
vdb-entry
technical-description
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now