Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-12042


The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload HTML files with arbitrary web scripts that will execute whenever a user accesses the file.


Published

2024-12-13T09:15:07.370

Last Modified

2025-05-22T14:33:24.273

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-434
  • Type: Primary
    CWE-79
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application inspireui mstore_api < 4.16.5 Yes

References