CVE-2026-16041
Received Received - Intake

Unauthenticated Review Creation in MStore API WordPress Plugin

Vulnerability report for CVE-2026-16041, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: WPScan

Description

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MStore API WordPress plugin before version 4.21.0 has a flaw in its REST API that allows unauthenticated users to create WooCommerce product reviews without verifying ownership or authorization. Attackers can set any reviewer name, email, and star rating, bypassing store settings that restrict reviews to verified purchasers.

Detection Guidance

Check if the MStore API plugin version is below 4.21.0 by inspecting the WordPress plugin directory or using commands like 'wp plugin list' in WP-CLI. Monitor for unauthorized product reviews with suspicious reviewer names or emails.

Impact Analysis

This vulnerability allows attackers to post fake reviews on your WooCommerce store, potentially misleading customers and damaging your store's reputation. It bypasses purchase verification, enabling spam or malicious reviews even if your store restricts reviews to buyers.

Mitigation Strategies

Immediately update the MStore API plugin to version 4.21.0 or later. Review recent product reviews for unauthorized entries and remove any suspicious ones. Ensure your WooCommerce store settings restrict reviews to verified purchasers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16041. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart