Description
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create or edit administrator accounts. WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud version 2.1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1.6 or latest
References
https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-mstore-api-plugin/
https://plugins.trac.wordpress.org/browser/mstore-api/trunk/mstore-api.php?rev=2247970
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-1999-0154)
WordPress Plugin WP-Polls SQL Injection (2.61)
WordPress Plugin Photo Gallery by Ays-Responsive Image Gallery SQL Injection (4.4.3)
Oracle Database Server CVE-2011-3512 Vulnerability (CVE-2011-3512)
PHP Incorrect Conversion between Numeric Types Vulnerability (CVE-2018-5711)