Vulnerability Details CVE-2020-36713
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated attackers to create new administrator accounts, delete existing administrator accounts, or escalate privileges on any account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.8%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2020-36713
-
cpe:2.3:a:inspireui:mstore_api:-
-
cpe:2.3:a:inspireui:mstore_api:1.0.0
-
cpe:2.3:a:inspireui:mstore_api:1.2.0
-
cpe:2.3:a:inspireui:mstore_api:1.3.0
-
cpe:2.3:a:inspireui:mstore_api:1.4.0
-
cpe:2.3:a:inspireui:mstore_api:2.0.0