Vulnerability record · CVE-2023-2732 · published 25 May 2023
CVE-2023-2732: MStore API WordPress plugin authentication bypass via REST add listing
Inspireui · Mstore Api
The MStore API plugin for WordPress fails to properly verify the user identity supplied in the add listing REST API request, allowing an attacker to authenticate as an arbitrary existing user. Because the flaw is reachable without authentication and the plugin is used on public-facing sites, it exposes full site takeover when an administrator user id is targeted.
Description
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a high EPSS score make this an urgent patch-first issue for any site running the affected plugin.
What it is
The MStore API plugin for WordPress fails to properly verify the user identity supplied in the add listing REST API request, allowing an attacker to authenticate as an arbitrary existing user. Because the flaw is reachable without authentication and the plugin is used on public-facing sites, it exposes full site takeover when an administrator user id is targeted.
Impact
An unauthenticated attacker can log in as any existing user, including an administrator, gaining full control of the WordPress site.
Attack surface
Reached over the network through the plugin's add listing REST API endpoint; no authentication or user interaction is required, only knowledge of a target user id.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is high at 0.675 (99th percentile) and references are patch and advisory only, indicating elevated likelihood of exploitation without confirmed in-the-wild activity.
What to do
- Update the MStore API plugin to a version later than 3.9.2, which contains the fix referenced in the plugin changeset.
- If immediate patching is not possible, disable the MStore API plugin until it can be updated.
- Restrict or block access to the plugin's listing REST API endpoints at the WAF or reverse proxy where feasible.
- Audit WordPress user accounts and rotate credentials for administrators and other privileged users.
- Monitor for unexpected new listings or administrative changes that could indicate abuse of the bypass.
Detection
- Review web server and WordPress logs for requests to the MStore API listing REST endpoints, especially from unauthenticated clients.
- Alert on authentication or session activity for privileged accounts that does not follow a normal login flow.
- Monitor for creation of new listings or content changes made by accounts shortly after suspicious REST API calls.
- Check for unexpected administrator account creation or privilege changes following plugin API traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-2732 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-2732), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.