CVE-2026-16038
Received Received - Intake

Unauthenticated Order Payment Bypass in MStore API WordPress Plugin

Vulnerability report for CVE-2026-16038, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: WPScan

Description

The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mstore_api mstore_api to 4.21.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MStore API WordPress plugin before version 4.21.0 has a flaw where payment-completion endpoints do not verify payments with the payment gateway before marking orders as paid. This allows unauthenticated attackers to fraudulently mark orders as fully paid without completing a transaction, enabling them to obtain goods or services for free.

Detection Guidance

To detect this vulnerability, check if your MStore API WordPress plugin version is below 4.21.0. Inspect payment-completion endpoints for missing payment verification with the gateway. Monitor for unauthorized order status changes marked as paid without transactions.

Impact Analysis

This vulnerability allows attackers to bypass payment and receive products or services without paying. For website owners, it results in financial losses due to unpaid orders. Users may face disrupted services or fraudulent transactions if the plugin is used on an e-commerce site.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR and HIPAA by enabling unauthorized access to goods or services without proper payment verification. Uncontrolled transactions may result in improper handling of personal or financial data, violating privacy and security requirements.

Mitigation Strategies

Update the MStore API WordPress plugin to version 4.21.0 or later to address the vulnerability. Disable or restrict access to payment-completion endpoints until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16038. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart