CVE-2026-54817
Deferred Deferred - Pending Action
Authentication Bypass in FluxBuilder MStore API

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
fluxbuilder mstore_api to 4.18.4 (inc)
patchstack mstore_api 4.18.4
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-54817 is a Broken Authentication vulnerability in the WordPress MStore API Plugin versions 4.18.4 and below. It allows unauthenticated attackers to bypass authentication mechanisms by exploiting an alternate path or channel, specifically targeting the password recovery process.

This flaw enables attackers to perform actions normally restricted to higher-privileged users, potentially gaining admin access to affected websites.

Impact Analysis

This vulnerability can have serious impacts as it allows attackers without any authentication to gain administrative privileges on affected websites.

  • Unauthorized access to sensitive administrative functions.
  • Potential full compromise of the affected website.
  • Increased risk of data manipulation, defacement, or further exploitation.

Because of its severity and ease of exploitation, it is expected to be targeted in mass-exploit campaigns.

Mitigation Strategies

Users are advised to update the WordPress MStore API Plugin to version 4.19.0 or later, as this version contains the patch for the vulnerability.

Until the update can be applied, Patchstack has provided a mitigation rule to block attacks targeting this vulnerability.

Compliance Impact

The vulnerability allows unauthenticated attackers to bypass authentication and potentially gain admin access to affected websites. Such unauthorized access can lead to improper handling or exposure of sensitive personal or health data, which may violate compliance requirements under standards like GDPR and HIPAA.

Failure to address this vulnerability could result in non-compliance with data protection regulations due to increased risk of data breaches and unauthorized data manipulation.

Therefore, organizations using affected versions of the MStore API should promptly apply the patch or mitigation to maintain compliance with these standards.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54817. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart