PT-2025-18761 · WordPress · Mstore Api+1

Brian Sans-Souci

·

Publicado

2025-05-02

·

Atualizado

2025-05-06

·

CVE-2025-3438

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress versions up to, and including, 4.17.4
Description The issue is related to limited privilege escalation due to a lack of restriction of role when registering, allowing unauthenticated attackers to register with the wcfm vendor role. This role is associated with the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress, and the vulnerability can only be exploited if this plugin is installed and activated.
Recommendations For versions up to, and including, 4.17.4, update to a version that includes the necessary security patches to restrict role registration. As a temporary workaround, consider restricting access to the registration process to prevent unauthenticated attackers from exploiting the lack of role restrictions.

Correção

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-3438

Produtos afetados

Mstore Api
Wcfm Marketplace