PT-2025-18761 · WordPress · Mstore Api+1

·

CVE-2025-3438

·

Published

2025-05-02

·

Updated

2025-05-06

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress versions up to, and including, 4.17.4
Description The issue is related to limited privilege escalation due to a lack of restriction of role when registering, allowing unauthenticated attackers to register with the wcfm vendor role. This role is associated with the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress, and the vulnerability can only be exploited if this plugin is installed and activated.
Recommendations For versions up to, and including, 4.17.4, update to a version that includes the necessary security patches to restrict role registration. As a temporary workaround, consider restricting access to the registration process to prevent unauthenticated attackers from exploiting the lack of role restrictions.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3438

Affected Products

Mstore Api
Wcfm Marketplace