← Vulnerability feed

Vulnerability record · CVE-2023-2732 · published 25 May 2023

CVE-2023-2732: MStore API WordPress plugin authentication bypass via REST add listing

Inspireui · Mstore Api

The MStore API plugin for WordPress fails to properly verify the user identity supplied in the add listing REST API request, allowing an attacker to authenticate as an arbitrary existing user. Because the flaw is reachable without authentication and the plugin is used on public-facing sites, it exposes full site takeover when an administrator user id is targeted.

9.8 CVSS 3.1 Critical EPSS 68% · top 0.7% CWE-288 · Authentication bypass via alternate path
9.8CVSS 3.1 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required and a high EPSS score make this an urgent patch-first issue for any site running the affected plugin.

What it is

The MStore API plugin for WordPress fails to properly verify the user identity supplied in the add listing REST API request, allowing an attacker to authenticate as an arbitrary existing user. Because the flaw is reachable without authentication and the plugin is used on public-facing sites, it exposes full site takeover when an administrator user id is targeted.

Impact

An unauthenticated attacker can log in as any existing user, including an administrator, gaining full control of the WordPress site.

Attack surface

Reached over the network through the plugin's add listing REST API endpoint; no authentication or user interaction is required, only knowledge of a target user id.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is high at 0.675 (99th percentile) and references are patch and advisory only, indicating elevated likelihood of exploitation without confirmed in-the-wild activity.

What to do

  • Update the MStore API plugin to a version later than 3.9.2, which contains the fix referenced in the plugin changeset.
  • If immediate patching is not possible, disable the MStore API plugin until it can be updated.
  • Restrict or block access to the plugin's listing REST API endpoints at the WAF or reverse proxy where feasible.
  • Audit WordPress user accounts and rotate credentials for administrators and other privileged users.
  • Monitor for unexpected new listings or administrative changes that could indicate abuse of the bypass.

Detection

  • Review web server and WordPress logs for requests to the MStore API listing REST endpoints, especially from unauthenticated clients.
  • Alert on authentication or session activity for privileged accounts that does not follow a normal login flow.
  • Monitor for creation of new listings or content changes made by accounts shortly after suspicious REST API calls.
  • Check for unexpected administrator account creation or privilege changes following plugin API traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-2732 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6328Inspireui mstore api authentication bypass via alternate path vulnerabilityThe MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and…EPSS 0.67%9.8CVE-2023-45055Inspireui mstore api sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This …EPSS 0.55%9.8CVE-2023-3277Inspireui mstore api authentication bypass via alternate path vulnerabilityThe MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 du…EPSS 2.9%9.8CVE-2023-3076Inspireui mstore api missing authorization vulnerabilityThe MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale …EPSS 2.2%9.8CVE-2023-3077Inspireui mstore api vulnerabilityThe MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL inje…EPSS 5.5%9.8CVE-2023-3197Inspireui mstore api sql injection vulnerabilityThe MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0…EPSS 3.9%9.8CVE-2020-36713Inspireui mstore api authentication bypass via alternate path vulnerabilityThe MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted acces…EPSS 1.6%9.8CVE-2023-2733Inspireui mstore api authentication bypass via alternate path vulnerabilityThe MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verif…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2023-2732), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.