Sceawere

Vulnerability Detail

CVE-2026-97219UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MStore API Improper Order Validation

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
16h ago
Vendor
Unknown
Product
MStore API
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-02T07:16:39.170Z",
  "pubdate": "2026-10-02T07:16:39.170Z",
  "executiveSummary": "The MStore API WordPress plugin contains an Improper Input Validation vulnerability that leads to unauthorized order status manipulation.\nThis vulnerability allows authenticated users with self-registered accounts to bypass payment gateways by directly modifying the internal state of their own orders.\nThe flaw stems from a lack of server-side restrictions on mutable order fields during API requests.\nAn attacker can exploit this to transition unpaid orders to 'paid' or 'fulfilled' statuses, effectively obtaining goods without financial transaction completion.\nThe vulnerability affects all versions of the MStore API WordPress plugin prior to 4.22.1.\nThe risk is critical, as it directly impacts revenue integrity and bypasses established e-commerce business logic through an unprivileged authentication vector.",
  "technicalDetails": "The root cause of this vulnerability is an Insecure Direct Object Reference (IDOR) combined with insufficient server-side validation of incoming API request parameters. The MStore API endpoint responsible for order updates fails to verify if the fields being submitted by the client are authorized for modification by the end-user.\nWhen a user performs an update request via the API, the application logic does not implement a 'deny-list' or strict 'allow-list' for order object properties. Consequently, the API accepts user-supplied input to overwrite critical database fields associated with the order object, specifically the 'status' field.\nAttack flow: 1. The attacker registers a standard customer account on the WordPress site. 2. The attacker initiates a purchase for specific goods through the front-end, creating an unpaid order record in the backend database. 3. Instead of proceeding to a payment gateway, the attacker intercepts or crafts an API request targeting the MStore order update endpoint. 4. The attacker includes the 'status' parameter in the JSON payload, setting the value to 'paid', 'completed', or 'fulfilled'. 5. The application processes the request, updates the database entry, and triggers downstream fulfillment actions, such as enabling digital downloads or notifying the shipping module that payment has been successfully captured.\nBecause the API treats this input as trusted data, it fails to cross-reference the requested state change with the actual transaction records provided by external payment processors. This allows an authenticated, low-privileged user to achieve unauthorized privilege escalation in the context of order management.\nAffected component: MStore API order management controller. Versions affected: < 4.22.1. Authentication requirements: Basic registered user account. Privilege requirements: Low (authenticated). Network exposure: Publicly accessible API endpoint. Post-exploitation impact: Financial loss, unauthorized access to digital goods, and potential disruption of inventory management systems."
}
CVE-2026-97219: MStore API Improper Order Validation (MEDIUM Severity, CVSS: 4.3) | Sceawere