Detects 'Authentication Bypass' vulnerability in inspireui MStore API plugin for WordPress affects v. through 3.9.2.


CVE-2023-2732 Scanner Detail

The Inspireui MStore API plugin for WordPress is a powerful tool used for connecting mobile apps with WooCommerce stores. This plugin is designed to make the process of building and managing online stores easier, faster and more efficient. The MStore API plugin enables developers and business owners to connect their WooCommerce store with a mobile app that can be accessed by their customers on different devices.

However, recently this popular plugin has been found to have a serious vulnerability flaw with the CVE-2023-2732 code. The vulnerability has been discovered in the authentication system of the plugin which can be easily bypassed, and it allows attackers to log in as any existing user on the site if they have access to their user id. The vulnerability is present in plugin versions up to and including 3.9.2.

This vulnerability can cause serious damage to a website if exploited by attackers. Hackers can gain access to sensitive information stored on the website such as usernames and passwords. The attackers can also execute malicious code and compromise the security of the website with little to no resistance.

