Description
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently take over any account. WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud version 3.1.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.0 or latest
References
https://blog.webble.fr/critical-authentication-bypass-in-mstore-api/
https://sploitus.com/exploit?id=WPEX-ID:BF5DDC43-974D-41FA-8276-C1A27D3CC882
https://plugins.svn.wordpress.org/mstore-api/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Sexy Add Template Cross-Site Request Forgery (1.0)
WordPress 4.6.x Cross-Domain Flash Injection Vulnerability (4.6 - 4.6.9)
WordPress Plugin Newsletter Subscription Form Possible Remote Code Execution (1.1.2)
WordPress 2.0.5 Charset Decoding SQL Injection Vulnerability (0.6.2 - 2.0.5)