CVE-2021-24148
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.37% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- inspireui/mstore api
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/bf5ddc43-974d-41fa-8276-c1a27d3cc882Third Party Advisory
- https://wpscan.com/vulnerability/bf5ddc43-974d-41fa-8276-c1a27d3cc882Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.