CVE-2023-3076

CRITICAL

WordPress MStore API <3.9.9 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-3076. PoCs published by im-hanzou.

AI-analyzed exploit summary This repository contains a script for exploiting CVE-2023-3076, an unauthenticated privilege escalation vulnerability in MStore API versions prior to 3.9.9. The exploit allows mass addition of admin users and PHP file uploads.

Description

The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.

Exploits (1)

nomisec WORKING POC 16 stars
by im-hanzou · poc
https://github.com/im-hanzou/MSAPer

This repository contains a script for exploiting CVE-2023-3076, an unauthenticated privilege escalation vulnerability in MStore API versions prior to 3.9.9. The exploit allows mass addition of admin users and PHP file uploads.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: MStore API < 3.9.9
No auth needed
Prerequisites: GNU Parallel installed · List of target URLs
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/ac662436-29d7-4ea6-84e1-f9e229b44f5b

Scores

CVSS v3 9.8
EPSS 0.0173
EPSS Percentile 74.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
inspireui/mstore_api < 3.9.9
Published Jul 10, 2023
Tracked Since Feb 18, 2026