The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.
2023-07-10T16:15:55.190
2024-11-21T08:16:42.123
Modified
CVSSv3.1: 3.5 (LOW)
-
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | inspireui | mstore_api | < 3.9.7 | Yes |