The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new posts.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Inspireui
Inspireui mstore Api |
|
CPEs | cpe:2.3:a:inspireui:mstore_api:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Inspireui
Inspireui mstore Api |
Tue, 27 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 27 May 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new posts. | |
Title | MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-05-27T01:48:48.377Z
Updated: 2025-05-27T19:54:10.468Z
Reserved: 2025-05-14T11:50:47.393Z
Link: CVE-2025-4683

Updated: 2025-05-27T19:54:04.927Z

Status : Analyzed
Published: 2025-05-27T03:15:24.040
Modified: 2025-07-07T15:55:52.187
Link: CVE-2025-4683

No data.