CVE-2023-3076
CRITICALWordPress MStore API <3.9.9 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-3076. PoCs published by im-hanzou.
AI-analyzed exploit summary This repository contains a script for exploiting CVE-2023-3076, an unauthenticated privilege escalation vulnerability in MStore API versions prior to 3.9.9. The exploit allows mass addition of admin users and PHP file uploads.
Description
The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.
Exploits (1)
This repository contains a script for exploiting CVE-2023-3076, an unauthenticated privilege escalation vulnerability in MStore API versions prior to 3.9.9. The exploit allows mass addition of admin users and PHP file uploads.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H