Skip to content

Known CVE

WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection

MStore API plugin for WordPress up to version 4.0.1 contains an unauthenticated blind SQL injection caused by insufficient escaping of 'id' parameter in SQL queries, letting attackers execute arbitrary SQL commands without authentication, exploit requires sending crafted requests with malicious 'id' parameter.

CVE-2023-3197

Critical2023

cve2023 · wordpress · wp-plugin · wp · sqli · mstore-api · unauth · time-based

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website