The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and 'firebase_sms_login_v2' functions. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email address or phone number. Additionally, if a new email address is supplied, a new user account is created with the default role, even if registration is disabled.
History

Wed, 21 May 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Inspireui
Inspireui mstore Api
Weaknesses CWE-862
CPEs cpe:2.3:a:inspireui:mstore_api:*:*:*:*:*:wordpress:*:*
Vendors & Products Inspireui
Inspireui mstore Api

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-07-12T10:59:56.085Z

Updated: 2024-08-01T21:33:05.461Z

Reserved: 2024-06-25T15:37:19.159Z

Link: CVE-2024-6328

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:05.461Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-12T11:15:11.630

Modified: 2025-05-21T20:49:00.123

Link: CVE-2024-6328

cve-icon Redhat

No data.