rootpwn

medium · CVSS v3 4.3 · EPSS 0.00185

CVE-2026-97219

The MStore API WordPress plugin (v<4.22.1) allows any authenticated user to change the status of their own unpaid orders to paid or fulfille

Overview

The MStore API WordPress plugin (v<4.22.1) allows any authenticated user to change the status of their own unpaid orders to paid or fulfilled. This can result in customers receiving goods without payment. The vulnerability is present in the order update endpoint.

Description

The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.

Impact

Confidentiality is not directly affected, but the integrity of order data is compromised, enabling fraudulent fulfillment. Availability is not impacted. Store owners and defenders are impacted as they may lose revenue and customer trust.

Remediation

Upgrade the MStore API plugin to version 4.22.1 or later. If an upgrade is not possible, restrict the order status update capability to administrators or implement role‑based checks. Monitor order status changes and audit logs for anomalous activity.

Risk context

The CVSS score of 4.3 indicates medium risk, and the EPSS of 0.00185 suggests low likelihood of exploitation. However, the potential loss of revenue and damage to customer trust warrant timely remediation.

Affected products

  • WordPress MStore API plugin

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
—
EPSS
0.00185

WordPress plugin order-fraud authentication defense ecommerce integrity

← All CVEs