CVE-2026-97219
Received Received - Intake

Unauthenticated Order Status Change in MStore API WordPress Plugin

Vulnerability report for CVE-2026-97219, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mstore_api mstore_api From 4.21.1 (inc) to 4.22.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the MStore API WordPress plugin before version 4.22.1 allows authenticated users with self-registerable accounts to change the status of their own unpaid orders to paid or fulfilled without making a payment. This effectively lets them receive goods without paying.

Detection Guidance

Check the installed version of the MStore API plugin in your WordPress environment. If the version is between 4.21.1 and 4.22.0, the system is vulnerable. Review order logs for unauthorized status changes from unpaid to paid or fulfilled by users without payment.

Impact Analysis

If you use the MStore API plugin in WordPress and have self-registerable accounts, attackers could exploit this to receive products without payment. This could lead to financial losses for your business and undermine trust in your order processing system.

Compliance Impact

This vulnerability could lead to unauthorized access to goods without payment, potentially violating financial transaction integrity requirements in standards like PCI DSS. It may also impact data integrity and accountability principles in GDPR and HIPAA if order status changes are logged or processed without proper authorization.

Mitigation Strategies

Update the MStore API plugin to version 4.22.1 or later immediately. Disable self-registerable accounts if not required. Monitor order status changes for suspicious activity and restrict user permissions to prevent unauthorized modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97219. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart