CVE-2024-8269

HIGH

MStore API - WordPress <4.15.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function. This makes it possible for unauthenticated attackers to create user accounts on sites, even when user registration is disabled and plugin functionality is not activated.

Scores

CVSS v3 7.3
EPSS 0.0038
EPSS Percentile 30.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
inspireui/MStore API – Create Native Android & iOS Apps On The Cloud < 4.15.3
inspireui/mstore_api < 4.15.4
Published Sep 13, 2024
Tracked Since Feb 18, 2026