What the vulnerability does
01Description
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function. This makes it possible for unauthenticated attackers to create user accounts on sites, even when user registration is disabled and plugin functionality is not activated.
Explanation of Vulnerability in Simple Terms
02Summary
MStore API versions up to 4.15.3 contain an access control flaw that allows unauthenticated attackers to read, modify, or delete data without proper authorization checks. The vulnerability affects the API layer and requires no user interaction. Site owners using this product should update immediately to a version newer than 4.15.3.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete data in the MStore API without authentication.
Potential impact on your site
04Site Impact
Unauthorized users can access, alter, or remove app data and configurations stored in MStore API.
Conditions required to exploit
05Prerequisites
Network access to the MStore API; no authentication or user interaction required.
Key dates
06Disclosure timeline
September 13, 2024
CVE published
April 8, 2026
Record updated