CVE-2020-36713

CRITICAL

MStore API < 2.1.5 - Unauthenticated Authentication Bypass via Unrestricted Register and Update User Profile Routes

Title source: llm
STIX 2.1

Description

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated attackers to create new administrator accounts, delete existing administrator accounts, or escalate privileges on any account.

Scores

CVSS v3 9.8
EPSS 0.0160
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-288 CWE-306
Status published
Products (2)
inspireui/MStore API – Create Native Android & iOS Apps On The Cloud < 2.1.6
inspireui/mstore_api < 2.1.5
Published Jun 07, 2023
Tracked Since Feb 18, 2026