CVE-2023-3277

CRITICAL EXPLOITED NUCLEI

Inspireui Mstore API < 4.10.7 - Privilege Escalation

Title source: rule

Description

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address.

Nuclei Templates (1)

MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
CRITICALVERIFIEDby daffainfo
FOFA: body="/wp-content/plugins/mstore-api/"

Scores

CVSS v3 9.8
EPSS 0.4488
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-06-19
CWE
CWE-288
Status published
Products (2)
inspireui/mstore_api < 4.10.7
inspireui/MStore API – Create Native Android & iOS Apps On The Cloud < 4.10.7
Published Nov 03, 2023
Tracked Since Feb 18, 2026