Description
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create or edit administrator accounts. WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud version 2.1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1.6 or latest
References
https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-mstore-api-plugin/
https://plugins.trac.wordpress.org/browser/mstore-api/trunk/mstore-api.php?rev=2247970