CVE-2023-3076

CRITICAL

WordPress MStore API <3.9.9 - Privilege Escalation

Title source: llm

Description

The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.

Exploits (1)

nomisec WORKING POC 16 stars
by im-hanzou · poc
https://github.com/im-hanzou/MSAPer

Scores

CVSS v3 9.8
EPSS 0.2915
EPSS Percentile 96.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (1)
inspireui/mstore_api < 3.9.9
Published Jul 10, 2023
Tracked Since Feb 18, 2026